Affected by GO-2024-3237
and 3 other vulnerabilities
GO-2024-3237: NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file system in github.com/NVIDIA/nvidia-container-toolkit
GO-2024-3239: NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability in github.com/NVIDIA/nvidia-container-toolkit
GO-2025-3992: NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path in github.com/NVIDIA/gpu-operator
GO-2025-3998: NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook in github.com/NVIDIA/gpu-operator
NewModifyingRuntimeWrapper creates a runtime wrapper that applies the specified modifier to the OCI specification
before invoking the wrapped runtime. If the modifier is nil, the input runtime is returned.