NVIDIAScape: OCI Hook Inheritance Flaws in AI Infra
by antisocial - Wednesday July 30, 2025 at 08:28 PM
#1
Taking a look at NVIDIAScape after its Pwn2Own reveal. CDI mode allows env vars like LD_PRELOAD to propagate through OCI hooks, inverting isolation for root execution on the host. More or less under-discussed aspect in shared AI clusters, this opens vectors for model exfiltration or poisoning, especially via tainted Hugging Face images in supply chains. Reminds me of older runc vulnerabilities, but the GPU element part takes it to another level, this vulnerability hitting roughly 37% of cloud AI services. I also found this a bit amateur like, because this is mostly privilege escalation for babies, and this coming from a very trusted company.
I wont bother writing a exploit since anyone with a brain can figure out how to abuse this.

Not sure if anyone else will find this interesting, but i did.
PGP ARCHIVE
contact: i@hateje.ws
Reply


Forum Jump:


 Users browsing this thread: 1 Guest(s)