Describe the bug
Running Trivy scanner on each of the component container images of GPU Operator v26.7.1 reports following CVEs:
| Severity |
Count |
Score range |
| Critical |
49 |
[9.0-10] |
| High |
3776 |
[7.0,9.0) |
| Medium |
8671 |
[4.0,7.0) |
| Low |
265 |
[1.0,4.0) |
Attached zip file nvidia-gpu-operator-cve-scan-results.zip
contains:
- Raw trivy json format reports
- CVS format summary grouped into per-severity directory (containing per container image csv data CVE ID, CVE score, package name, package version)
- A script to transform json raw data into CVS data
To Reproduce
- Enumerate all container images from GPU Operator helm chart
- Run trivy scanner to generate json format report per container image, e.g.
docker run --rm aquasec/trivy:0.74.0 image --format json "<container-image-path>" > "<container-image-name-version.json>"
- Run the json2csv.sh script to generate CVE report, summary.
Expected behavior
Our customers deploying Nvidia GPU Operator have a security policy prohibiting OSS packages with any Critical and High CVEs (i.e. CVE score >= 7.0), their policy requires
- either fixes to CVEs
- or per-CVE non-exploitability confirmation/explanation
- or per-CVE mitigation actions
Environment (please provide the following information):
- GPU Operator Version: v26.7.1
- OS: Ubuntu 24.04.4 LTS
- Kernel Version: 6.17.0-35-generic
- Container Runtime Version: containerd://2.2.5+vmware.1-fips
- Kubernetes Distro and Version: VMware Kubernetes Service - VMware Kubernetes Release v1.35.6+vmware.1
Describe the bug
Running Trivy scanner on each of the component container images of GPU Operator v26.7.1 reports following CVEs:
Attached zip file nvidia-gpu-operator-cve-scan-results.zip
contains:
To Reproduce
Expected behavior
Our customers deploying Nvidia GPU Operator have a security policy prohibiting OSS packages with any Critical and High CVEs (i.e. CVE score >= 7.0), their policy requires
Environment (please provide the following information):