Affected by GO-2024-3237
and 3 other vulnerabilities
GO-2024-3237: NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file system in github.com/NVIDIA/nvidia-container-toolkit
GO-2024-3239: NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability in github.com/NVIDIA/nvidia-container-toolkit
GO-2025-3992: NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path in github.com/NVIDIA/gpu-operator
GO-2025-3998: NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook in github.com/NVIDIA/gpu-operator
CUDA represents a CUDA image that can be used for GPU computing. This wraps
a map of environment variable to values that can be used to perform lookups
such as requirements.
HasDisableRequire checks for the value of the NVIDIA_DISABLE_REQUIRE. If set
to a valid (true) boolean value this can be used to disable the requirement checks
IsLegacy returns whether the associated CUDA image is a "legacy" image. An
image is considered legacy if it has a CUDA_VERSION environment variable defined
and no NVIDIA_REQUIRE_CUDA environment variable defined.