Impact
Vulnerability: NVIDIA Container Toolkit for Linux includes a race condition where the system performs a time‑of‑check, time‑of‑use (TOCTOU) operation on files used by the runtime. Based on the description, the attack seems to involve manipulating container configuration or the underlying file system to trigger the race condition. The flaw, classified as CWE‑367, permits an attacker to influence container configuration or the underlying filesystem to cause the runtime to use a file or resource that has changed after validation. Successful exploitation can lead to arbitrary code execution inside the container or on the host, is followed by privilege escalation, and allows tampering with data.
Affected Systems
All currently released versions of NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux are affected. No version ranges are listed, so all deployed installations should be treated as vulnerable until a patch removes the race condition.
Risk and Exploitability
The CVSS score of 8.5 marks this flaw as high severity, while the EPSS score of <1% indicates a low likelihood of real-world exploitation at present. The attack vector, inferred from the description, appears to target file handling during container execution. The vulnerability is not listed in the CISA KEV catalog, and an exploitation could lead to arbitrary code execution with elevated privileges and the ability to modify critical data.
OpenCVE Enrichment