CVE-2024-0134

NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-05 19:15

Updated : 2024-11-08 15:53


NVD link : CVE-2024-0134

Mitre link : CVE-2024-0134

CVE.ORG link : CVE-2024-0134


JSON object : View

Products Affected

nvidia

  • nvidia_gpu_operator
  • nvidia_container_toolkit

linux

  • linux_kernel
CWE
CWE-61

UNIX Symbolic Link (Symlink) Following

NVD-CWE-Other