Affected by GO-2024-3237
and 3 other vulnerabilities
GO-2024-3237: NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file system in github.com/NVIDIA/nvidia-container-toolkit
GO-2024-3239: NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability in github.com/NVIDIA/nvidia-container-toolkit
GO-2025-3992: NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path in github.com/NVIDIA/gpu-operator
GO-2025-3998: NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook in github.com/NVIDIA/gpu-operator
MergeDeviceSpecs creates a device with the specified name which combines the edits from the previous devices.
If a device of the specified name already exists, an error is returned.