Site icon TheCyberThrone

NVIDIA Container Toolkit TOCTOU Vulnerability CVE-2024-0132

Advertisements

Security researchers  from Wiz has uncovered a  critical vulnerability in the NVIDIA Container Toolkit could allow a container to escape and gain full access to the underlying host.

The vulnerability tracked as CVE-2024-0132 with a CVSS score 9.0 is a Time-of-check Time-of-Use (TOCTOU) issue that impacts NVIDIA Container Toolkit 1.16.1 or earlier.

Advertisements

The NVIDIA Container Toolkit designed to facilitate the deployment and management of GPU-accelerated containers. It enables users to build and run containers that leverage NVIDIA GPUs, making it particularly valuable for applications requiring high-performance computing, such as machine learning and data analysis.

Researchers reported the vulnerability to NVIDIA on September 1st, 2024. The company did not disclose technical details of attacks exploiting this issue due to its impact.

This issue impacts any AI applications using a vulnerable container toolkit for GPU support, whether in the cloud or on-premises.

Mode of Operandi

NVIDIA addressed the issue on September 26, 2024, with the release of the NVIDIA Container Toolkit version 1.16.2 and NVIDIA GPU Operator 24.6.2.

Advertisements

According to Wiz, 33% of cloud environments are impacted by this vulnerability, the data was analyzed by Wiz Research across 100K+ public cloud environments. This figure highlights the serious nature of the CVE-2024-0132 vulnerability and the importance of taking steps to mitigate it.

Exit mobile version