Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-24260

Опубликовано: 01 июл. 2026
Источник: redhat
CVSS3: 8.5

Описание

NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering.

A flaw was found in NVIDIA Container Toolkit. An attacker could exploit a time-of-check time-of-use (TOCTOU) race condition. This vulnerability might allow an attacker to achieve code execution, escalate privileges, and tamper with data.

Отчет

A flaw was found in NVIDIA Container Toolkit versions through 1.19.0, where a time-of-check time-of-use (TOCTOU) race condition could allow an attacker to achieve code execution, privilege escalation, and data tampering. Red Hat ships NVIDIA Container Toolkit version 1.19.1 in RHEL 9 and RHEL 10, which includes the fix for this vulnerability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nvidia-container-toolkitNot affected
Red Hat Enterprise Linux 9nvidia-container-toolkitNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2496027NVIDIA Container Toolkit: NVIDIA Container Toolkit: Privilege escalation and code execution via race condition

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.5
nvd
около 1 месяца назад

NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering.

CVSS3: 8.5
github
около 1 месяца назад

NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering.

8.5 High

CVSS3