How Wiz found a Critical NVIDIA AI vulnerability: Deep Dive into a container escape (CVE-2024-0132)
ID: 79dfe6c5-1b99-5977-87ca-0100f0f04a0c
STIX ID: report--79dfe6c5-1b99-5977-87ca-0100f0f04a0c
Feed Name: Wiz Blog
Wiz Research discovered and disclosed a critical container-escape vulnerability in the NVIDIA Container Toolkit (CVE-2024-0132) with a subsequent bypass (CVE-2025-23359). By exploiting a TOC/TOU weakness in libnvidia-container mounts, an attacker controlling a container image can cause host filesystems to be mounted into the container and then use host Unix sockets (e.g., docker.sock) to spawn privileged containers, enabling full host compromise across Docker, containerd, CRI-O and some gVisor deployments; fixes are available in NVIDIA Container Toolkit 1.17.4 and the report includes detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
