Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Researchers believe that the new exploit is bypassing the Nvidia container corrected vulnerability
Global Security

Researchers believe that the new exploit is bypassing the Nvidia container corrected vulnerability

AdminBy AdminFebruary 12, 2025No Comments2 Mins Read
NVIDIA Container Toolkit Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


February 12, 2025Red LakshmananThe safety of the container / vulnerability

Nvidia Container Toolkit vulnerability

Cybersecurity researchers have found a bypass for the NVIDIA container’s safety vulnerability, which can be used to escape the container and gain full access to the main host.

New vulnerability is tracked as Cve-2025-2359 (CVSS assessment: 8.3). This affects the following versions –

  • Nvidia Container Toolkit (all versions up to 1.17.3) – recorded in version 1.17.4
  • GPU Nvidia operator (all versions up to 24.9.1) – recorded in version 24.9.2
Cybersecurity

‘NVIDIA container’s tools for Linux contains time of use (Bakery) Vulnerability when used with the default configuration where a container image can access the host file system, “the company said on Tuesday.

“The successful feat of this vulnerability can lead to the code, refusal to service, escalation of privileges, disclosure and data fraud.”

https://www.youtube.com/watch?v=om5xyzkeoak

Wiz wiz that cloudy safety that general Additional technical specificity of this deficiency stated that this is bypass for another vulnerability (Cve-2024-0132CVSS assessment: 9.0), which was addressed to Nvidia in September 2024.

In a nutshell, the vulnerability allows the bad actors to install the hoste root system in the container, giving them unobstructed access to all files. In addition, access can be used to launch privileged containers and reaching full compromise of the host through the Unix socket.

Wiz Shir Tamari, Ronen Shustin and Andres Riancho Researchers have stated (ie root catalog) on ​​a way within “/USR/lib64.”

Cybersecurity

While access to the host file system provided by the container is only read, this restriction can be bypassed by interacting with unix sockets to spawns new privileged containers and gain unlimited access to the file system.

“This elevated access levels also allowed us to control network traffic, renew active processes and perform a number of other operations at the host level,” the researchers said.

In addition to the upgrade to the latest version, Nvidia Container Tools are recommended not to disable “-no-Cntlibs” flag Under production conditions.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.