CVE-2024-0132 Container Escape Vulnerability affecting NVIDIA Container Toolkit
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. The supported impact is full host system access. Reported affected versions include < 1.16.2.
What Happened
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. The supported impact is full host system access. Reported affected versions include < 1.16.2.
Why This Matters
Publisher reporting describes a concrete security event. BugSkan could not yet bind it to a CVE or affected version, so treat the source details as the current record.
Recommended Action
Upgrade github.com/NVIDIA/nvidia-container-toolkit to 1.16.2 or later. Identify deployments of NVIDIA Container Toolkit matching the evidenced affected versions: < 1.16.2.
Exposure
Exposure unknown
Oct 12, 2025 05:30
Exposure reason: This incident does not currently match a technology in My AI Stack.
Exploitation status: UNKNOWN
Affected versions: < 1.16.2
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.
Timeline
-
Incident first seen
Oct 12, 2025 05:30BugSkan first recorded this incident.
-
Generative AI Security: Risks & Best Practices - wiz.io
Oct 12, 2025 05:30wiz.io · Vulnerability
Sources
wiz.io · Oct 12, 2025 05:30
The NVIDIA Container Toolkit contains a critical security flaw, identified as CVE-2024-0132, which allows for container escape. This vulnerability grants attackers full host system access, highlighting a significant risk in AI infrastructure.
Open publisher sourceMy AI Stack Match
Create an account to see which incidents overlap with your AI stack.