KAI Scheduler: Missing authentication on API endpoints
CVSS 7.7CVE-2026-24177NVIDIA / GPU stackcurated
Impact
Missing authentication on API endpoints -> scheduler manipulation
Who can reach it
Network-adjacent attacker inside the cluster
What to do
Upgrade KAI Scheduler chart; add network policy in front of the API
References
Related entries
- KAI Scheduler: Improper access control in resource allocation (cross-tenant quota abuse)CVE-2026-24176 · KAI SchedulerMedium
- NVIDIA Windows GPU driver: out-of-bounds read with no privileges required, leaking data and crashing the driverCVE-2026-47576 · NVIDIA GPU Display Driver for Windows (kernel module)High
- Linux amdgpu: unbounded FRU PIA TLV walk reads out of bounds on malformed EEPROM dataCVE-2026-97428 · Linux kernel drm/amdgpu (FRU EEPROM PIA/TLV parser)High
- DGX H100 BMC (IPMI): Credential exposureCVE-2023-25531 · DGX H100 BMC (IPMI)High
- NVIDIA License System - Delegated Licensing Service (DLS): An unauthorised action against the DLS reaches partialCVE-2024-0122 · NVIDIA License System - Delegated Licensing Service (DLS)High
- Container Toolkit / GPU Operator: Container escape to host root (insufficient input validation)CVE-2024-0135 · Container Toolkit / GPU OperatorHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.