cbcvebase.
CVE-2025-23266
published 2025-07-17

CVE-2025-23266: NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary…

PriorityP351critical9CVSS 3.1
AVAACLPRLUINSCCHIHAH
EPSS
2.54%
83.1th percentile
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.

Affected

8 ranges
VendorProductVersion rangeFixed in
github.comnvidia_gpu-operator>= 0 < 25.3.225.3.2
github.comnvidia_k8s-device-plugin>= 0 < 0.17.30.17.3
github.comnvidia_mig-parted>= 0 < 0.12.20.12.2
github.comnvidia_nvidia-container-toolkit>= 0 < 1.17.81.17.8
msrcazl3_nvidia-container-toolkit_1.15.0-1_on_azure_linux_3.0
msrccbl2_nvidia-container-toolkit_1.11.0-1_on_cbl_mariner_2.0
nvidiacontainer_toolkit
nvidiacontainer_toolkit

CVSS provenance

nvdv3.19.0CRITICALCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_msrc9.0CRITICAL
vendor_redhat9.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.