CVE-2024-0134
Nov. 8, 2024, 3:53 p.m.
Tags
CVSS Score
Products Impacted
Vendor | Product | Versions |
---|---|---|
nvidia |
|
|
linux |
|
|
Description
NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.
Weaknesses
CWE-61
UNIX Symbolic Link (Symlink) Following
The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
CWE ID: 61Date
Published: Nov. 5, 2024, 7:15 p.m.
Last Modified: Nov. 8, 2024, 3:53 p.m.
Status : Analyzed
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
psirt@nvidia.com
CPEs
Type | Vendor | Product | Version | Update | Edition | Language | Software Edition | Target Software | Target Hardware | Other Information |
---|---|---|---|---|---|---|---|---|---|---|
a | nvidia | nvidia_container_toolkit | / | / | / | / | / | / | / | / |
a | nvidia | nvidia_gpu_operator | / | / | / | / | / | / | / | / |
o | linux | linux_kernel | - | / | / | / | / | / | / | / |
CVSS Data
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Base Score
Exploitability Score
Impact Score
Base Severity
MEDIUMCVSS Vector String
The CVSS vector string provides an in-depth view of the vulnerability metrics.
View Vector StringCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N