NVIDIAScape: OCI Hook Inheritance Flaws in AI Infra
by antisocial - Wednesday July 30, 2025 at 08:28 PM
#1
Taking a look at NVIDIAScape after its Pwn2Own reveal. CDI mode allows env vars like LD_PRELOAD to propagate through OCI hooks, inverting isolation for root execution on the host. More or less under-discussed aspect in shared AI clusters, this opens vectors for model exfiltration or poisoning, especially via tainted Hugging Face images in supply chains. Reminds me of older runc vulnerabilities, but the GPU element part takes it to another level, this vulnerability hitting roughly 37% of cloud AI services. I also found this a bit amateur like, because this is mostly privilege escalation for babies, and this coming from a very trusted company.
I wont bother writing a exploit since anyone with a brain can figure out how to abuse this.

Not sure if anyone else will find this interesting, but i did.
PGP ARCHIVE
contact: i@hateje.ws
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Dokan Pro Unauthenticated SQL Injection POC | CVSS 10 Loki 41 3,688 Yesterday, 05:18 PM
Last Post: Xploitd
  {SECRET} DATABASE OF EXPLOITS lulagain 435 26,431 Yesterday, 06:11 AM
Last Post: DirtyEra
  New Zer0 Day Wordpress A3g00n 81 3,358 Yesterday, 03:06 AM
Last Post: DirtyEra
  Wordpress Elementor 3.11.6 Exploit - Full Takeover TheGoodlife 102 19,721 May 04, 2026, 06:45 AM
Last Post: eztocard
  new wordpress website takeover vuln (video + poc ) zinzeur 314 28,338 Apr 30, 2026, 03:54 PM
Last Post: baku

Forum Jump:


 Users browsing this forum: 1 Guest(s)