GPU VulnDB

Database/NVIDIA / GPU stack

Intel Gaudi software installer: The Gaudi software installer leaves files and directories with permissions that let

CVE-2024-45067NVIDIA / GPU stackcurated

Impact

The Gaudi software installer leaves files and directories with permissions that let a non-root local user modify components that later run as root. That is a straight local root path on any node where the Gaudi stack was installed with the affected installer - and root on a Gaudi node means every tenant's job on that node.

Who can reach it

Any local authenticated user on a node that has the Gaudi stack installed. Node images built once and cloned across the fleet propagate the bad permissions everywhere.

What to do

Upgrade the Gaudi software installer to 1.18 or later, and re-check permissions on nodes already provisioned - upgrading the package does not always repair permissions set by an earlier install. Rebuild the golden node image rather than patching in place. No firmware or BIOS component.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.