CVE-2024-0133
Package
libnvidia-container-tools
(DEB / RPM Packages)
Affected versions
< 1.16.1
Patched versions
1.16.2
libnvidia-container1
(DEB / RPM Packages)
< 1.16.1
1.16.2
Description
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.
Patches
The fix has been addressed in
v1.16.2
of thelibnvidia-container*
packages that are bundled with the NVIDIA Container Toolkit v1.16.2.References