Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-0136


NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.


Published

2025-01-28T03:15:07.433

Last Modified

2025-10-06T14:07:29.840

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.6 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-653

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nvidia nvidia_container_toolkit < 1.17.3 Yes
Application nvidia nvidia_gpu_operator < 24.9.1 Yes
Operating System linux linux_kernel - No

References