Skip to content

[Bug]: Latest Nvidia GPU Operator v26.7.1 reports large numbers of critical and high CVEs in Trivy scan output #2991

Description

@nikhaild

Describe the bug
Running Trivy scanner on each of the component container images of GPU Operator v26.7.1 reports following CVEs:

Severity Count Score range
Critical 49 [9.0-10]
High 3776 [7.0,9.0)
Medium 8671 [4.0,7.0)
Low 265 [1.0,4.0)

Attached zip file nvidia-gpu-operator-cve-scan-results.zip
contains:

  • Raw trivy json format reports
  • CVS format summary grouped into per-severity directory (containing per container image csv data CVE ID, CVE score, package name, package version)
  • A script to transform json raw data into CVS data

To Reproduce

  • Enumerate all container images from GPU Operator helm chart
  • Run trivy scanner to generate json format report per container image, e.g.
docker run --rm aquasec/trivy:0.74.0 image --format json "<container-image-path>" > "<container-image-name-version.json>"
  • Run the json2csv.sh script to generate CVE report, summary.

Expected behavior

Our customers deploying Nvidia GPU Operator have a security policy prohibiting OSS packages with any Critical and High CVEs (i.e. CVE score >= 7.0), their policy requires

  • either fixes to CVEs
  • or per-CVE non-exploitability confirmation/explanation
  • or per-CVE mitigation actions

Environment (please provide the following information):

  • GPU Operator Version: v26.7.1
  • OS: Ubuntu 24.04.4 LTS
  • Kernel Version: 6.17.0-35-generic
  • Container Runtime Version: containerd://2.2.5+vmware.1-fips
  • Kubernetes Distro and Version: VMware Kubernetes Service - VMware Kubernetes Release v1.35.6+vmware.1

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions