CVE Vulnerabilities

CVE-2024-0135

Improper Isolation or Compartmentalization

Published: Jan 28, 2025 | Modified: Oct 06, 2025
CVSS 3.x
7.6
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.6 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Ubuntu

NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Weakness

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Affected Software

Name Vendor Start Version End Version
Nvidia_container_toolkit Nvidia * 1.17.3 (excluding)
Nvidia_gpu_operator Nvidia * 24.9.1 (excluding)

Potential Mitigations

References