Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments
ID: 37c83123-a387-5118-bebd-a0dc3077f8d9
STIX ID: report--37c83123-a387-5118-bebd-a0dc3077f8d9
Feed Name: Wiz Blog
Wiz Research disclosed CVE-2024-0132, a critical container-escape vulnerability in the NVIDIA Container Toolkit that allows attackers controlling a container image to mount the host filesystem and escalate to full host takeover; the flaw affects GPU-enabled containerized AI workloads (including Kubernetes with the NVIDIA GPU Operator) and is particularly severe in environments that run untrusted images or allow customers to load their own GPU images—NVIDIA released patches (Container Toolkit v1.16.2, GPU Operator v24.6.2) on Sept 26, 2024 and organizations are urged to prioritize patching and runtime validation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
