Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-0137


NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to denial of service and escalation of privileges.


Published

2025-01-28T03:15:07.567

Last Modified

2025-10-06T14:08:34.033

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-653

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nvidia nvidia_container_toolkit < 1.17.3 Yes
Application nvidia nvidia_gpu_operator < 24.9.1 Yes
Operating System linux linux_kernel - No

References