nvidia-container-toolkit: Data tampering in NVIDIA Container Toolkit
Published Sep 26, 2024
4.8
MEDIUMCVSS 4.0
EPSS 0.25%
Description
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.
Affected products
-
- Version All versions up to and including v1.16.1StatusaffectedConstraints-
- Version
-
- Version All versions up to and including 24.6.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| NVIDIA | Container Toolkit | unaffected |
| ||||||
| NVIDIA | GPU Operator | unaffected |
|
Configuration 1
- < 1.16.2
Running on/with
- n/a
Configuration 2
- < 24.6.2
Running on/with
- n/a
No data.
Red Hat Enterprise Linux AI (RHEL AI)
rhelai1/bootc-nvidia-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) | rhelai1/bootc-nvidia-rhel9 | Not affected | n/a |
github.com/NVIDIA/nvidia-container-toolkit
Go
Introduced 0 Fixed 1.16.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/NVIDIA/nvidia-container-toolkit | 0 | 1.16.2 |
Remediation
Red Hat statement
Due to certain circumstances, this vulnerability in the NVIDIA Container Toolkit is not affecting Red Hat Products and is rated as Important severity rather than Critical. First, a specifically crafted container image is required for effective exploitation. Only Red Hat Signed containers are offered. Additionally, user interaction is required for exploitation, further reducing the likelihood of an attack. Most importantly, this vulnerability does not impact use cases that comply with our operating procedures by utilizing the Container Device Interface (CDI). As a result, this vulnerability does not affect Red Hat products because of the use of CDI. Furthermore, for an attacker to deploy a crafted container image, they would need an environment that permits untrusted containers, which is a scenario that is not typical for Red Hat customers.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (10)
- https://access.redhat.com/security/cve/CVE-2024-0133 Vendor Advisory
- https://advisory-inbox.githubapp.com/advisory_reviews/GHSA-wqq7-v22c-gpfp
- https://bugzilla.redhat.com/show_bug.cgi?id=2314825 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-3026 Advisory
- https://github.com/NVIDIA/libnvidia-container/security/advisories/GHSA-xff4-h7r9-vrpf
- https://github.com/NVIDIA/nvidia-container-toolkit/security/advisories/GHSA-f748-7hpg-88ch
- https://github.com/advisories/GHSA-f748-7hpg-88ch Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-0133
- https://nvidia.custhelp.com/app/answers/detail/a_id/5582 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-0133
Change history (0)
No recorded changes yet.