Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Incomplete patch at Nvidia Toolkit Leapes Cve-2024-0132 open to escape containers
Global Security

Incomplete patch at Nvidia Toolkit Leapes Cve-2024-0132 open to escape containers

AdminBy AdminApril 10, 2025No Comments3 Mins Read
Incomplete Patch in NVIDIA Toolkit
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


April 10, 2025Red LakshmananThe safety of the container / vulnerability

Incomplete patch at Nvidia Toolkit

Cybersecurity researchers have talked about incomplete patch for a previously addressed security deficiency, which affects the NVIDIA Container toolkit, which can be threatened by successful use.

Original vulnerability Cve-2024-0132 (CVSS assessment: 9.0) -This vulnerability of time checking (TOCTOU), which can lead to the attack of the container and allow unauthorized access to the main host.

Although this deficiency was resolved by Nvidia in September 2024, the new Trend Micro analysis showed that the correction would be incomplete, and that there is also a related efficiency that affects the Docker on Linux, which could lead to a service refusal (DOS).

Cybersecurity

“These problems can allow attackers to avoid the container’s insulation, access to resources that feel access – Note In a new report published today.

The fact that the vulnerability of TOCTOUS means that a specially created container can be abused to access the Hosto file and execution of arbitrary commands with root privileges. The disadvantage affects the version 1.17.4 if the function allows CUDA-Compat-Libs-under the container is clearly included.

“Specific drawback exists in Mount_files function”, Trend Micro – Note. “The problem arises as a result of the lack of proper blocking when performing operations at the facility. The attacker can use this vulnerability to escalate privileges and perform arbitrary code in the context of the host.”

However, for this privilege of escalation to work, the attacker must have been able to execute the code in the container.

Near was the Cve ID has been assigned Cve-2025-2359 (CVSS Assessment: 9.0), which previously was labeled Wiz Wiz Cloud Security Wiz, as well as treatment for CVE-2024-0132 back in February 2025. It was address In version 1.17.4.

Cybersecurity company said it also revealed the productivity problem during the CVE-2024-0132 analysis, which could potentially lead to DOS vulnerability by the host car. This affects the Docker instances on Linux Systems.

Cybersecurity

“If a new container with multiple mounts, customized (Bind-Propagation = common), several parents/children are created.

“This leads to the rapid and uncontrolled growth of the attachment table, the debilitating available file descriptors (FD). After all, the Docker is unable to create new containers with the fD exhaust.

To soften the problem, it is recommended to monitor the Linux mounting table for pathological growth, limit Docker API to authorized staff, pursue a solid access control policy and pursue periodic checks of the file system, attachment of volumes and socket connection.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025

Learn the smarter way to protect modern applications

May 16, 2025

Meta to train AI on EU users since May 27 without consent; NOIB is threatened by lawsuits

May 15, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025

Learn the smarter way to protect modern applications

May 16, 2025

Meta to train AI on EU users since May 27 without consent; NOIB is threatened by lawsuits

May 15, 2025

Coinbase agents are bribed, data ~ 1% of users were traced; Attempted extortion of $ 20 million will not succeed

May 15, 2025

NPM malicious package uses Unicode Steganography, Google Calendar as C2 Chroper

May 15, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.