Container Toolkit: Container escape to host filesystem (bypass of the CVE-2024-0132 fix)
Impact
Container escape to host filesystem (bypass of the CVE-2024-0132 fix)
Who can reach it
Any tenant that can run an arbitrary container image
What to do
Bump nvidia-container-toolkit to 1.17.4+ and restart the runtime on every GPU node; upgrade GPU Operator to 24.9.2+; evict tenant workloads
Fleet impact
How widespread
Universal - all versions <= 1.17.3, i.e. everyone who thought they had already patched 0132
Cost to remediate
daemon-restart to 1.17.4 / GPU Operator 24.9.2 - a second forced patch cycle across the same fleet within five months
Why it hits the whole fleet
Proves the class is not one-and-done: a mount-path TOCTOU bypass re-opens host filesystem access from a crafted container, so every operator who patched in Sept 2024 had to re-patch the whole fleet in Feb 2025
References
Related entries
- Container Toolkit: Unauthorized empty-file creation on the hostCVE-2024-0133 · Container ToolkitMedium
- Container Toolkit: Container escape to host filesystem via TOCTOU in the **default** configurationCVE-2024-0132 · Container ToolkitCritical
- Container Toolkit: Container escape to host root via malicious image (LD_PRELOAD in OCI hook)CVE-2025-23266 · Container ToolkitCritical
- Container Toolkit: Container escape / host file write via symlink followingCVE-2025-23267 · Container ToolkitHigh
- Container Toolkit: Container escape to host root via TOCTOU raceCVE-2026-24260 · Container ToolkitHigh
- Jetson Xavier / Orin: Authentication bypass in a network serviceCVE-2026-24148 · Jetson Xavier / OrinHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.