Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

SUSE 2026 libnvidia-container Important Security Update for 2024-0132-0133

suse
Calendar Grey February 16, 2026
Dist Suse Esm H88
Update for libnvidia-container resolves critical security issues including data tampering and TOCTOU race conditions.
An update that solves two vulnerabilities can now be installed.

Summary

## This update for libnvidia-container fixes the following issues: Update to version 1.18.0. Security issues fixed: * CVE-2024-0132: time-of-check time-of-use (TOCTOU) race condition in default configuration via specifically crafted container image (bsc#1231033). * CVE-2024-0133: data tampering in host file system via specially crafted container image (bsc#1231032). Other updates and bugfixes: * updated to 1.18.0 * Add clock_gettime to allowed syscalls * Fix pointer accessing local variable out of scope * Require version match between libnvidia-container-tools and libnvidia- container1 * Add libnvidia-gpucomp.so to the list of compute libs * Use VERSION_ prefix for version parts in makefiles * Add additional logging * Do not discard container flags when --cuda-compat-mode is not specified

References

* bsc#1231032

* bsc#1231033

Cross-

* CVE-2024-0132

* CVE-2024-0133

CVSS scores:

* CVE-2024-0132 ( SUSE ): 8.9

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

* CVE-2024-0132 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

* CVE-2024-0132 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

* CVE-2024-0132 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

* CVE-2024-0133 ( SUSE ): 2.1

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

* CVE-2024-0133 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

* CVE-2024-0133 ( NVD ): 4.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N

* CVE-2024-0133 ( NVD ): 3.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N

Affected Products:

* Containers Module 15-SP7

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:0558-1
Release Date: 2026-02-16T11:42:52Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here