VYPR

apk package

chainguard/nvidia-container-toolkit-nvidia-ctk-installer

pkg:apk/chainguard/nvidia-container-toolkit-nvidia-ctk-installer

Vulnerabilities (27)

  • CVE-2024-0134Nov 5, 2024
    affected < 1.17.4-r0fixed 1.17.4-r0

    NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful explo

  • CVE-2024-0133Sep 26, 2024
    affected < 1.16.2-r0fixed 1.16.2-r0

    NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerab

  • CVE-2024-0132Sep 26, 2024
    affected < 1.16.2-r0fixed 1.16.2-r0

    NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A su

  • CVE-2024-34158HigSep 6, 2024
    affected < 1.16.1-r1fixed 1.16.1-r1

    Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.

  • CVE-2024-34156HigSep 6, 2024
    affected < 1.16.1-r1fixed 1.16.1-r1

    Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

  • CVE-2024-34155MedSep 6, 2024
    affected < 1.16.1-r1fixed 1.16.1-r1

    Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stack exhaustion.

  • CVE-2024-24788MedMay 8, 2024
    affected < 1.15.0-r1fixed 1.15.0-r1

    A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.

Page 2 of 2