GPU VulnDB

Database/NVIDIA / GPU stack

Container Toolkit: Container escape to host filesystem via TOCTOU in the **default** configuration

CVE-2024-0132NVIDIA / GPU stackcurated

Impact

Container escape to host filesystem via TOCTOU in the **default** configuration

Who can reach it

Any tenant that can run an arbitrary container image on a GPU node

What to do

Bump nvidia-container-toolkit to 1.16.2+ and restart the container runtime on every GPU node; upgrade GPU Operator to 24.6.2+; evict and re-admit tenant workloads

Fleet impact

How widespread

Universal - all versions <= 1.16.1, i.e. the entire installed base at disclosure

Cost to remediate

daemon-restart to 1.16.2 / GPU Operator 24.6.2; hosts that ran untrusted images need node-drain + rebuild because the host-filesystem write has already happened

Why it hits the whole fleet

TOCTOU in the mount path lets a crafted container image mount the host filesystem and execute code as root - the canonical "one CVE, every GPU node in the fleet" event

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.