CVE-2024-0137 Details
Description
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to denial of service and escalation of privileges.
An improper isolation vulnerability has been identified in the NVIDIA Container Toolkit, where a specially crafted container image could allow untrusted code to execute in the host's network namespace. This issue arises only when the toolkit is not configured with default settings. Exploitation of this vulnerability could result in a denial of service and unauthorized privilege escalation.
To address this vulnerability, users should update to NVIDIA Container Toolkit version 1.17.3 or later. Instructions for updating can be found in the NVIDIA Container Toolkit documentation. Additionally, ensure that the toolkit is configured with the default settings to prevent untrusted code from executing in the host's network namespace.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5599 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-653 | Improper Isolation or Compartmentalization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nvidia nvidia container toolkit | < 1.17.3 |
CPE
Remediation
| |
| nvidia nvidia gpu operator | < 24.9.1 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 6, 2025 | Initial Analysis | [email protected] |
| Jan 28, 2025 | New CVE Received | [email protected] |