cbcvebase.
CVE-2025-23266
published 2025-07-17

CVE-2025-23266: NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary…

critical9CVSS 3.1
AVAACLPRLUINSCCHIHAH
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.

Affected

8 ranges
VendorProductVersion rangeFixed in
github.comnvidia_gpu-operator>= 0 < 25.3.225.3.2
github.comnvidia_k8s-device-plugin>= 0 < 0.17.30.17.3
github.comnvidia_mig-parted>= 0 < 0.12.20.12.2
github.comnvidia_nvidia-container-toolkit>= 0 < 1.17.81.17.8
msrcazl3_nvidia-container-toolkit_1.15.0-1_on_azure_linux_3.0
msrccbl2_nvidia-container-toolkit_1.11.0-1_on_cbl_mariner_2.0
nvidiacontainer_toolkit
nvidiacontainer_toolkit