NVIDIA Container Toolkit是美国英伟达(NVIDIA)公司的一个容器工具包。允许用户构建和运行 GPU 加速的容器。 NVIDIA Container Toolkit 1.16.1及之前版本存在安全漏洞,该漏洞源于在默认配置下使用时包含检查时间使用时间(TOCTOU)漏洞,成功利用此漏洞可能会导致代码执行、拒绝服务、权限提升、信息泄露和数据篡改。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NVIDIA | Container Toolkit | All versions up to and including v1.16.1 | - |
|
| NVIDIA | GPU Operator | All versions up to and including 24.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2024-0132 – Fully Weaponized NVIDIA Container Toolkit Exploit | https://github.com/r0binak/CVE-2024-0132 | POC Details |
| 2 | None | https://github.com/ssst0n3/poc-cve-2024-0132 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet