logo

An NVIDIA Container Bug & Chance to Harden Kubernetes

ID: 48774781-2b34-57f1-9567-8217b2c53fb7

STIX ID: report--48774781-2b34-57f1-9567-8217b2c53fb7

Feed Name: Dark Reading

Threat Score

Date Published: 2025-07-09

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Executive Summary: CVE-2024-0132 is a critical TOCTOU vulnerability in the NVIDIA Container Toolkit that can enable container escapes and full host/Kubernetes cluster compromise by allowing attackers to mount the host root filesystem and access container runtime sockets; Wiz researchers demonstrated practical exploits against cloud and AI providers and recommend mitigations including enabling user namespaces, applying network policies, and restricting Kubelet permissions to reduce impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.