Описание
NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering.
A flaw was found in NVIDIA Container Toolkit. An attacker could exploit a time-of-check time-of-use (TOCTOU) race condition. This vulnerability might allow an attacker to achieve code execution, escalate privileges, and tamper with data.
Отчет
A flaw was found in NVIDIA Container Toolkit versions through 1.19.0, where a time-of-check time-of-use (TOCTOU) race condition could allow an attacker to achieve code execution, privilege escalation, and data tampering. Red Hat ships NVIDIA Container Toolkit version 1.19.1 in RHEL 9 and RHEL 10, which includes the fix for this vulnerability.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | nvidia-container-toolkit | Not affected | ||
| Red Hat Enterprise Linux 9 | nvidia-container-toolkit | Not affected |
Показывать по
Дополнительная информация
Статус:
8.5 High
CVSS3
Связанные уязвимости
NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering.
NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering.
8.5 High
CVSS3