ZeroHour

CVE-2024-0136

CVSS 3.1
8.4 high
EPSS
<1%p50
Published
()
Modified
Description

NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Vendors
nvidia
Products
nvidia container toolkit, nvidia gpu operator
Weakness
CWE-653
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.