Target Industry
Indiscriminate, opportunistic targeting.
Overview
A critical security flaw has been identified in the NVIDIA Container Toolkit, potentially allowing attackers to escape container confines and gain full access to the host system. Known as CVE-2024-0132, this vulnerability has a CVSS score of 9.0.
Impact
Exploiting this vulnerability could lead to unauthorised data access, code execution, privilege escalation, information disclosure, and denial-of-service attacks. It is particularly concerning as it has the potential for supply chain attacks, where a rogue container image could grant attackers extensive control over the host. The vulnerability also threatens multi-tenant environments by enabling attackers to access data and secrets of other applications running on the same node or cluster.
Vulnerability Detection
NVIDIA has released a security update addressing the security flaw in the respective product versions. As such, previous versions are vulnerable to potential exploits.
Exploitation
A threat actor could exploit the critical vulnerability in the NVIDIA Container Toolkit by crafting a rogue container image. When this malicious image is executed on the target platform, whether directly by an unsuspecting user or indirectly through automated processes. It could grant the attacker full access to the host’s file system. However, there is no evidence of proof of concept at the moment of writing.
Containment, Mitigations & Remediations
Update the NVIDIA Container Toolkit to version v1.16.2 and the NVIDIA GPU Operator to version
24.6.2, as these updates contain essential patches that address the vulnerability.
Threat Landscape
NVIDIA’s dominance in the graphics processing unit (GPU) market is well-established. The threat landscape surrounding the critical NVIDIA Container Toolkit vulnerability (CVE-2024-0132) is both complex and severe, posing significant risks to organisations across various sectors.
Threat Group
No attribution to specific threat actors or groups has been identified at the time of writing.
Further Information
· https://www.wiz.io/blog/wiz-research-critical-nvidia-ai-vulnerability












