NVIDIAScape: OCI Hook Inheritance Flaws in AI Infra
by antisocial - Wednesday July 30, 2025 at 08:28 PM
#1
Taking a look at NVIDIAScape after its Pwn2Own reveal. CDI mode allows env vars like LD_PRELOAD to propagate through OCI hooks, inverting isolation for root execution on the host. More or less under-discussed aspect in shared AI clusters, this opens vectors for model exfiltration or poisoning, especially via tainted Hugging Face images in supply chains. Reminds me of older runc vulnerabilities, but the GPU element part takes it to another level, this vulnerability hitting roughly 37% of cloud AI services. I also found this a bit amateur like, because this is mostly privilege escalation for babies, and this coming from a very trusted company.
I wont bother writing a exploit since anyone with a brain can figure out how to abuse this.

Not sure if anyone else will find this interesting, but i did.
PGP ARCHIVE
contact: i@hateje.ws
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  New Zer0 Day Wordpress A3g00n 83 4,047 Yesterday, 08:17 PM
Last Post: j4ng0
  {SECRET} DATABASE OF EXPLOITS lulagain 441 28,082 Yesterday, 05:41 PM
Last Post: chiki
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 69 3,702 Yesterday, 03:55 PM
Last Post: fkmonkey
  CVE-2024-32002 RCE PoC HA_twck 2 565 Yesterday, 01:33 PM
Last Post: newxiao1
  Cisco Secure Firewall Management Center(CVE-2026-20131) DirtyEra 0 135 Yesterday, 01:40 AM
Last Post: DirtyEra

Forum Jump:


 Users browsing this forum: 1 Guest(s)