vendor:
NVIDIA Container Toolkit
by:
r0binak
6.1
CVSS
HIGH
Time-of-check Time-of-Use (TOCTOU) Vulnerability
TOCTOU-53
CWE
Product Name: NVIDIA Container Toolkit
Affected Version From: 1.16.1
Affected Version To: 1.16.1
Patch Exists: NO
Related CWE: CVE-2024-0132
CPE: a:nvidia:nvidia_container_toolkit:1.16.1
Platforms Tested: Linux
2025
Container Breakout with NVIDIA Container Toolkit
NVIDIA Container Toolkit 1.16.1 and earlier versions are vulnerable to a Time-of-check Time-of-Use (TOCTOU) exploit. An attacker can leverage a specially crafted container image to access the host file system when default configurations are used. This exploit could result in various consequences such as code execution, denial of service, privilege escalation, information disclosure, and data manipulation.
Mitigation:
To mitigate this vulnerability, it is recommended to update NVIDIA Container Toolkit to a patched version that addresses the TOCTOU vulnerability. Additionally, limit access to containers and avoid running containers with unnecessary privileges.