CVE-2024-0132
NVIDIA Container Toolkit TOCTOU File System Vulnerability
Description
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
INFO
Published Date :
Sept. 26, 2024, 6:15 a.m.
Last Modified :
Oct. 2, 2024, 2:45 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
Affected Products
The following products are affected by CVE-2024-0132
vulnerability.
Even if cvefeed.io
is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
CVSS Scores
Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
---|---|---|---|---|---|---|
CVSS 3.1 | CRITICAL | [email protected] | ||||
CVSS 3.1 | HIGH | [email protected] |
Solution
- Upgrade to NVIDIA Container Toolkit version 1.16.2 or later.
- Update the affected packages.
Public PoC/Exploit Available at Github
CVE-2024-0132 has a 6 public
PoC/Exploit
available at Github.
Go to the Public Exploits
tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2024-0132
.
URL | Resource |
---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5582 | Vendor Advisory |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2024-0132
is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2024-0132
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
None
CVE-2024-0132 – Fully Weaponized NVIDIA Container Toolkit Exploit
container-breakout exploit nvidia-container-toolkit nvidia-gpu-operator cve-2024-0132
Dockerfile
News about technology and digital stuff
None
Dockerfile Shell
Archived EGI SVG Advisories
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
security cve exploit poc vulnerability
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2024-0132
vulnerability anywhere in the article.

-
The Hacker News
Critical NVIDIA Container Toolkit Flaw Allows Privilege Escalation on AI Cloud Services
Jul 18, 2025Ravie LakshmananCloud Security / AI Security Cybersecurity researchers have disclosed a critical container escape vulnerability in the NVIDIA Container Toolkit that could pose a severe t ... Read more

-
Dark Reading
Patch Now: NVDIA Flaws Expose AI Models, Critical Infrastructure
Source: Arletta Cwalina via Alamy Stock PhotoResearchers are urging enterprises that rely on NVIDIA GPUs for their artificial intelligence (AI) workloads to ensure that systems are patched against cri ... Read more

-
Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Incomplete Patch Leaves NVIDIA and Docker Users at Risk
Trend Micro found major flaws in the NVIDIA Container Toolkit and Docker, risking container escapes, DoS attacks and AI infrastructure. Users should audit setups and apply fixes. Trend Micro Research ... Read more

-
Daily CyberSecurity
SVG Phishing Surge: How Image Files Are Being Weaponized to Steal Credentials
SVG-Based Phishing Attack Flow | Image: Trustwave SpiderLabs In a world where images are meant to inform or entertain, a new breed of phishing attack is using them to deceive and steal. A recent repor ... Read more

-
Daily CyberSecurity
CVE-2024-0132: Incomplete NVIDIA Toolkit Patch Enables Container Escape and DoS Attacks
A recent report by Trend Research has uncovered that NVIDIA’s September 2024 security update for a critical vulnerability (CVE-2024-0132) in the NVIDIA Container Toolkit was incomplete, posing a signi ... Read more

-
Cyber Security News
NVIDIA’s Incomplete Patch for Critical Flaw Lets Attackers Steal AI Model Data
A critical vulnerability in NVIDIA’s Container Toolkit, CVE-2024-0132, remains exploitable due to an incomplete patch, endangering AI infrastructure and sensitive data. Coupled with a newly discovered ... Read more

-
The Hacker News
Incomplete Patch in NVIDIA Toolkit Leaves CVE-2024-0132 Open to Container Escapes
Container Security / Vulnerability Cybersecurity researchers have detailed a case of an incomplete patch for a previously addressed security flaw impacting the NVIDIA Container Toolkit that, if succes ... Read more

-
Trend Micro
Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
Summary: Trend Research identified that NVIDIA’s September 2024 security update for a critical vulnerability (CVE-2024-0132) in the NVIDIA Container Toolkit was incomplete, leaving systems potentially ... Read more

-
The Cyber Express
CISA Appoints Karen Evans as New Cybersecurity Executive Assistant Director
Karen Evans has been appointed as the new Executive Assistant Director (EAD) for Cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA). In this new role, Evans brings an extensi ... Read more

-
The Hacker News
Researchers Find New Exploit Bypassing Patched NVIDIA Container Toolkit Vulnerability
Container Security / Vulnerability Cybersecurity researchers have discovered a bypass for a now-patched security vulnerability in the NVIDIA Container Toolkit that could be exploited to break out of a ... Read more

-
Cybersecurity News
Chrome Patches Multi Vulnerabilities in Latest Stable Release
Google has rolled out a crucial update to its Chrome browser, addressing three high-severity security flaws that could be exploited by attackers. The update, versions 130.0.6723.69/.70 for Windows and ... Read more

-
Cybersecurity News
HORUS Protector: The New Undetectable Malware Crypter Threatening Cybersecurity
In a recent discovery by the SonicWall Capture Labs threat research team, a new malware crypter known as “HORUS Protector” has emerged, presenting a significant threat to cybersecurity defenses. This ... Read more

-
The Cyber Express
The Week’s Top Vulnerabilities: Cyble Urges Fixes for NVIDIA, Adobe, CUPS
Cyble researchers had a busy week, investigating 19 vulnerabilities in the week ended Oct.1 and flagging eight of them as high priority. Cyble’s weekly IT vulnerability report also noted that research ... Read more

-
Cybersecurity News
Prince Ransomware Hits UK and US via Royal Mail Phishing Scam
PDF containing a Dropbox URL | Image: Proofpoint Cybersecurity researchers at Proofpoint have uncovered a new phishing campaign that impersonates the British postal service, Royal Mail, to distribute ... Read more

-
The Cyber Express
86% of Users Neglect Critical Router Security, Says Latest Survey
It is not just enough to surf the internet, but equally important to safeguard its boundaries. However, a latest survey has exposed the knowledge and preparedness of internet users. It was found that ... Read more

-
Cybersecurity News
CVE-2024-47070: Critical Flaw in authentik Identity Provider Allows Authentication Bypass
A critical security vulnerability (CVE-2024-47070) has been discovered in the popular Identity Provider (IdP) and Single Sign-On (SSO) solution, authentik. Rated with a high CVSS score of 9.1, this fl ... Read more

-
europa.eu
Cyber Brief 24-10 - September 2024
Cyber Brief (September 2024)October 1, 2024 - Version: 1.0TLP:CLEARExecutive summaryWe analysed 269 open source reports for this Cyber Brief1.Relating to cyber policy and law enforcement, in Europe, l ... Read more

-
The Cyber Express
Critical Vulnerability in NVIDIA Container Toolkit Poses Risks to Cloud Environments
A new vulnerability in NVIDIA’s software impacts over 35% of cloud environments. The NVIDIA vulnerability, designated as CVE-2024-0132, is linked to the NVIDIA Container Toolkit, a widely utilized fra ... Read more

-
TheCyberThrone
CISA KEV Update Part VII – September 2024
The US CISA has added 4 vulnerabilities to its Known Exploited Vulnerability Catalog, based on the evidence of exploitationCVE-2019-0344 SAP Commerce Cloud Deserialization of Untrusted Data Vulnerabil ... Read more

-
TheCyberThrone
Storm-0501 deploys Embargo Ransomware in Hybrid Cloud Environment
Security researchers from Microsoft has observed the threat actor tracked as Storm-0501 launching a multi-staged attack where they compromised hybrid cloud environments and performed lateral movement ... Read more
The following table lists the changes that have been made to the
CVE-2024-0132
vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Oct. 02, 2024
Action Type Old Value New Value Added CVSS V3.1 NIST AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H Changed Reference Type https://nvidia.custhelp.com/app/answers/detail/a_id/5582 No Types Assigned https://nvidia.custhelp.com/app/answers/detail/a_id/5582 Vendor Advisory Added CWE NIST CWE-367 Added CPE Configuration AND OR *cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:* versions up to (excluding) 1.16.2 OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* Added CPE Configuration AND OR *cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:* versions up to (excluding) 24.6.2 OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* -
CVE Received by [email protected]
Sep. 26, 2024
Action Type Old Value New Value Added Description NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. Added Reference NVIDIA Corporation https://nvidia.custhelp.com/app/answers/detail/a_id/5582 [No types assigned] Added CWE NVIDIA Corporation CWE-367 Added CVSS V3.1 NVIDIA Corporation AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H