GHSA-f748-7hpg-88ch
GitHub Security Advisory
NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file system
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.
Affected Packages
Go
github.com/NVIDIA/nvidia-container-toolkit
Affected versions:
0
(fixed in 1.16.2)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 3, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.