CVE-2024-0132: NVIDIA: CVE-2024-0132 Container Toolkit 1.16.1 and Earlier Time-of-check Time-of Use Vulnerability

Overview

Severity
High (CVSS 8.3)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Category
Remote Code Execution
Exploit Status
Not Exploited
Patch Tuesday
2024-Oct
Released
2024-10-09
Last Updated
2024-10-23
EPSS Score
3.75% (percentile: 88.0%)

FAQ

What actions do customers need to take to protect themselves from this vulnerability? Customers with Ubuntu Linux or Azure Linux based Azure Kubernetes Service (AKS) Node Pools using NVIDIA GPU driver configurations are affected by this vulnerability. Please see below for details on how to update your resources to be protected against this vulnerability. Customers with Azure Linux based AKS Node Pool resources must manually install AKS Node image version 2024.1009.1 to be protected against this vulnerability by running the following CLI command: tdnf install https://packages.microsoft.com/cbl-mariner/2.0/prod/base/x86_64/Packages/n/nvidia-container-toolkit-1.16.2-1.cm2.x86_64.rpm Note: The AKS node image, version 20241009.1, will be deployed in November and contain this package by default. Customers can monitor the status of this deployment by using AKS Release Tracker. Customers with Ubuntu Linux based AKS Node Pool resources must manually upgrade the driver version of their AKS Nodes to version 202410.09.0 to be protected against this vulnerability by following the guidance here: AKS Node Image Upgrade. Note: This upgrade will not alter your Kubernetes version.

Detection & Weaponization (1 sources)

Maturity: Exploit

  • GitHub PoC: 2 repositories

Affected Products (6)

Mariner

  • CBL Mariner 2.0 ARM
  • CBL Mariner 2.0 x64
  • Azure Linux 3.0 ARM
  • Azure Linux 3.0 x64

Azure

  • Azure Kubernetes Service Node on Azure Linux
  • Azure Kubernetes Service Node on Ubuntu Linux

Security Updates (2)

Revision History

  • 2024-10-09: Information published.
  • 2024-10-23: In the Security Updates table, added Azure Kubernetes Service Node on Azure Linux and Azure Kubernetes Service Node on Ubuntu Linux because these product are also affected by this vulnerability. Microsoft strongly recommends that customers using these products install the updates to be fully protected from the vulnerability.