The NVIDIA Container Toolkit allows users to build and run NVIDIA GPU
accelerated containers. The toolkit includes a container runtime library and
utilities to automatically configure containers to leverage NVIDIA GPUs.
Update Information:
Update to 1.17.3 Fixes CVE-2024-0134 or GHSA-7jm9-xpwx-v999 Fixes CVE-2024-0135 or GHSA-9v84-cc9j-pxr6, CVE-2024-0136 or GHSA- vcfp-63cx-4h59, and CVE-2024-0137 or GHSA-frhw-w3wm-6cw4
* Wed Jan 29 2025 Debarshi Ray
[ 1 ] Bug #2324084 - CVE-2024-0134 golang-github-nvidia-container-toolkit: specially-crafted container image can lead to the creation of unauthorized files on the host [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2324084
[ 2 ] Bug #2342485 - CVE-2024-0135 golang-github-nvidia-container-toolkit: Improper Isolation or Compartmentalization in NVIDIA Container Toolkit [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2342485
[ 3 ] Bug #2342489 - CVE-2024-0137 golang-github-nvidia-container-toolkit: Improper Isolation or Compartmentalization in NVIDIA Container Toolkit [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2342489
[ 4 ] Bug #2342493 - CVE-2024-0136 golang-github-nvidia-container-toolkit: Improper Isolation or Compartmentalization in NVIDIA Container Toolkit [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2342493
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a15b07073f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.