CVE-2025-23359
- EPSS 0.33%
- Published 12.02.2025 01:15:09
- Last modified 25.09.2025 13:50:04
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability...
CVE-2024-0135
- EPSS 0.17%
- Published 28.01.2025 03:15:07
- Last modified 06.10.2025 14:06:00
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, esc...
CVE-2024-0136
- EPSS 0.17%
- Published 28.01.2025 03:15:07
- Last modified 06.10.2025 14:07:29
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container...
CVE-2024-0137
- EPSS 0.1%
- Published 28.01.2025 03:15:07
- Last modified 06.10.2025 14:08:34
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability is present only when the NVIDIA Container Toolkit...
CVE-2024-0134
- EPSS 0.14%
- Published 05.11.2024 19:15:05
- Last modified 08.11.2024 15:53:40
NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by a...
CVE-2024-0133
- EPSS 0.29%
- Published 26.09.2024 06:15:04
- Last modified 02.10.2024 14:43:22
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A succe...
CVE-2024-0132
- EPSS 5.24%
- Published 26.09.2024 06:15:02
- Last modified 02.10.2024 14:45:36
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use...