GPU VulnDB

Database/NVIDIA / GPU stack

Container Toolkit: Unauthorized empty-file creation on the host

CVE-2024-0133NVIDIA / GPU stackcurated

Impact

Unauthorized empty-file creation on the host

Who can reach it

Any tenant with a crafted container image

What to do

Bump toolkit + restart runtime

Fleet impact

How widespread

Universal - same package, same install base

Cost to remediate

daemon-restart (1.16.2)

Why it hits the whole fleet

Sibling TOCTOU allowing creation of arbitrary files on the host from inside a container; low severity alone but a stepping stone to host compromise on shared nodes

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.