NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.
2024-09-26T06:15:04.053
2024-10-02T14:43:22.433
Analyzed
CVSSv3.1: 4.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nvidia | nvidia_container_toolkit | < 1.16.2 | Yes |
Operating System | linux | linux_kernel | - | No |
Application | nvidia | nvidia_gpu_operator | < 24.6.2 | Yes |
Operating System | linux | linux_kernel | - | No |