Skip to content

Commit 4a00ae6

Browse files
authored
Add security page (#161)
Signed-off-by: Abigail McCarthy <[email protected]>
1 parent 9804d64 commit 4a00ae6

File tree

2 files changed

+100
-0
lines changed

2 files changed

+100
-0
lines changed

gpu-operator/index.rst

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,7 @@
3131
gpu-driver-upgrades.rst
3232
install-gpu-operator-vgpu.rst
3333
install-gpu-operator-nvaie.rst
34+
Security Considerations <security.rst>
3435

3536

3637

gpu-operator/security.rst

Lines changed: 99 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,99 @@
1+
2+
*****************************
3+
Security Considerations
4+
*****************************
5+
6+
7+
Pod Security Context of the Operator and Operands
8+
=================================================
9+
10+
Several of the NVIDIA GPU Operator operands, such as the driver containers and container toolkit,
11+
require the following elevated privileges:
12+
13+
- ``privileged: true``
14+
- ``hostPID: true``
15+
- ``hostIPC: true``
16+
17+
The elevated privileges are required for the following reasons:
18+
19+
- Access to the host file system and hardware devices, such as NVIDIA GPUs.
20+
- Restart system services such as containerd.
21+
- Loading and unloading kernel modules.
22+
23+
Only the Kubernetes cluster administrator needs to access or manage the Operator namespace.
24+
As a best practice, establish proper security policies and prevent any other users from accessing the Operator namespace.
25+
26+
27+
CVEs
28+
=================================================
29+
30+
The following is a list of known CVEs in the GPU Operator or its operands.
31+
To view any published security bulletins for NVIDIA products published security bulletins for NVIDIA products, refer to the NVIDIA product security page at https://www.nvidia.com/en-us/security/.
32+
33+
.. list-table:: CVEs
34+
:widths: 20 45 35
35+
:header-rows: 1
36+
37+
* - CVE ID
38+
- Affected Components
39+
- Fixed Version
40+
41+
* - `NVIDIA CVE-2025-23359 <https://nvidia.custhelp.com/app/answers/detail/a_id/5616>`_
42+
- NVIDIA Container Toolkit, all versions up to and including 1.17.3
43+
44+
NVIDIA GPU Operator, all versions up to and including 24.9.1
45+
- NVIDIA Container Toolkit 1.17.4
46+
47+
NVIDIA GPU Operator 24.9.2
48+
49+
* - `NVIDIA CVE-2024-0135 <https://nvidia.custhelp.com/app/answers/detail/a_id/5599>`_
50+
- NVIDIA Container Toolkit, all versions up to and including 1.17.2
51+
52+
NVIDIA GPU Operator, all versions up to and including 24.9.0
53+
- NVIDIA Container Toolkit 1.17.3
54+
55+
NVIDIA GPU Operator 24.9.1
56+
57+
* - `NVIDIA CVE-2024-0136 <https://nvidia.custhelp.com/app/answers/detail/a_id/5599>`_
58+
- NVIDIA Container Toolkit, all versions up to and including 1.17.2
59+
60+
NVIDIA GPU Operator, all versions up to and including 24.9.0
61+
- NVIDIA Container Toolkit 1.17.3
62+
63+
NVIDIA GPU Operator 24.9.1
64+
65+
* - `NVIDIA CVE-2024-0137 <https://nvidia.custhelp.com/app/answers/detail/a_id/5599>`_
66+
- NVIDIA Container Toolkit, all versions up to and including 1.17.2
67+
68+
NVIDIA GPU Operator, all versions up to and including 24.9.0
69+
- NVIDIA Container Toolkit 1.17.3
70+
71+
NVIDIA GPU Operator 24.9.1
72+
73+
* - `NVIDIA CVE-2024-0134 <https://nvidia.custhelp.com/app/answers/detail/a_id/5585>`_
74+
- NVIDIA Container Toolkit, all versions up to and including 1.16.2
75+
76+
NVIDIA GPU Operator, all versions up to and including 24.6.2
77+
- NVIDIA Container Toolkit 1.17.0
78+
79+
NVIDIA GPU Operator 24.9.0
80+
81+
* - `NVIDIA CVE-2024-0132 <https://nvidia.custhelp.com/app/answers/detail/a_id/5582>`_
82+
- NVIDIA Container Toolkit, all versions up to and including 1.16.1
83+
84+
NVIDIA GPU Operator, all versions up to and including 24.6.1
85+
- NVIDIA Container Toolkit 1.16.2
86+
87+
NVIDIA GPU Operator 24.6.2
88+
* - `NVIDIA CVE-2024-0133 <https://nvidia.custhelp.com/app/answers/detail/a_id/5582>`_
89+
- NVIDIA Container Toolkit, all versions up to and including 1.16.1
90+
91+
NVIDIA GPU Operator, all versions up to and including 24.6.1
92+
- NVIDIA Container Toolkit 1.16.2
93+
94+
NVIDIA GPU Operator 24.6.2
95+
96+
Report a Vulnerability
97+
-----------------------------
98+
99+
For details on reporting a suspected vulnerability, refer to the `GPU Operator Security policies <https://github.com/NVIDIA/gpu-operator/blob/main/SECURITY.md/>`_ page.

0 commit comments

Comments
 (0)