Skip to content

nvidia-container-toolkit CVE-2024-0132

High
rpkelly published GHSA-pvq6-2652-v9ph Oct 1, 2024

Package

nvidia-container-toolkit (bottlerocket)

Affected versions

< 1.24.0

Patched versions

1.24.0

Description

A flaw was found in nvidia-container-toolkit where a specifically crafted container image may gain access to the host file system, which could lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Severity

High

CVE ID

CVE-2024-0132

Weaknesses

No CWEs