NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.
| Software | From | Fixed in |
|---|---|---|
github.com/NVIDIA/nvidia-container-toolkit
|
- | 1.17.8 |
github.com/NVIDIA/k8s-device-plugin
|
- | 0.17.3 |
github.com/NVIDIA/gpu-operator
|
- | 25.3.2 |
github.com/NVIDIA/mig-parted
|
- | 0.12.2 |