Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-15935 | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
Mon, 06 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel Nvidia nvidia Container Toolkit Nvidia nvidia Gpu Operator |
|
| CPEs | cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:* cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux
Linux linux Kernel Nvidia nvidia Container Toolkit Nvidia nvidia Gpu Operator |
Tue, 28 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jan 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | nvidia-container-toolkit: Improper Isolation or Compartmentalization in NVIDIA Container Toolkit | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 28 Jan 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Weaknesses | CWE-653 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: nvidia
Published:
Updated: 2025-01-28T15:15:51.481Z
Reserved: 2023-12-02T00:42:47.163Z
Link: CVE-2024-0136
Updated: 2025-01-28T14:46:56.740Z
Status : Analyzed
Published: 2025-01-28T03:15:07.433
Modified: 2025-10-06T14:07:29.840
Link: CVE-2024-0136
OpenCVE Enrichment
Updated: 2025-07-12T16:01:14Z
EUVD