
PEACH
Un framework di isolamento del tenant
CVE-2026-24260 is a time-of-check time-of-use (TOCTOU) race condition vulnerability in NVIDIA Container Toolkit for Linux. It affects all versions of NVIDIA Container Toolkit up to and including 1.19.0, and NVIDIA GPU Operator up to and including 26.3.1. The vulnerability was disclosed on July 1, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 8.5 (High), assigned by NVIDIA Corporation (GitHub Advisory, NVIDIA Security).
The vulnerability is classified as CWE-367 (Time-of-check Time-of-use Race Condition), where the toolkit checks the state of a resource before using it, but the resource's state can change between the check and the use in a way that invalidates the check's results. An authenticated, low-privileged attacker can exploit this race condition remotely over the network without user interaction, though the attack complexity is rated High due to the timing requirements involved. Successful exploitation requires winning the race window between the check and use operations within the container runtime environment. Related attack patterns include CAPEC-27 (Leveraging Race Conditions via Symbolic Links) and CAPEC-29 (Leveraging TOCTOU Race Conditions) (GitHub Advisory, NVIDIA Security).
Successful exploitation of this vulnerability can result in arbitrary code execution, escalation of privileges within the container environment, and data tampering. The CVSS scope is rated as Changed, meaning a successful exploit can affect resources beyond the vulnerable component itself — potentially enabling container escape or compromise of the underlying host system. Confidentiality, integrity, and availability are all rated as High impact, indicating a total technical impact on affected systems (GitHub Advisory, NVIDIA Security).
NVIDIA has released a patch addressing this vulnerability; users should update NVIDIA Container Toolkit to a version beyond 1.19.0 and NVIDIA GPU Operator to a version beyond 26.3.1. As interim measures, administrators should restrict network access to container management interfaces to trusted networks only, and apply the principle of least privilege to limit which users can interact with the container toolkit. Monitoring container runtime logs for suspicious timing patterns or anomalous resource access sequences is also recommended (NVIDIA Security, GitHub Advisory).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."