NVIDIA Container Toolkit Improper Isolation Vulnerability Allowing Untrusted Code in Host Network Namespace
Vulnerability
An improper isolation vulnerability has been identified in the NVIDIA Container Toolkit, where a specially crafted container image could allow untrusted code to execute in the host's network namespace. This issue arises only when the toolkit is not configured with default settings. Exploitation of this vulnerability could result in a denial of service and unauthorized privilege escalation.
Impact
Exploitation of this vulnerability could lead to a denial of service and unauthorized escalation of privileges.
Remediation
To address this vulnerability, users should update to NVIDIA Container Toolkit version 1.17.3 or later. Instructions for updating can be found in the NVIDIA Container Toolkit documentation. Additionally, ensure that the toolkit is configured with the default settings to prevent untrusted code from executing in the host's network namespace.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
