CVE-2024-0135
Package
libnvidia-container-tools
(Debian / RPM packages)
Affected versions
< 1.17.3
Patched versions
1.17.3
libnvidia-container1
(Debian / RPM packages)
< 1.17.3
1.17.3
Description
NVIDIA Container Toolkit 1.17.1 or earlier contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Patches
The fix has been addressed in
v1.17.2of thelibnvidia-container*packages that are bundled with the NVIDIA Container Toolkit v1.17.2.References