CVE-2025-23266
published 2025-07-17CVE-2025-23266: NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary…
PriorityP351critical9CVSS 3.1
AVAACLPRLUINSCCHIHAH
EPSS
2.54%
83.1th percentile
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | nvidia_gpu-operator | >= 0 < 25.3.2 | 25.3.2 |
| github.com | nvidia_k8s-device-plugin | >= 0 < 0.17.3 | 0.17.3 |
| github.com | nvidia_mig-parted | >= 0 < 0.12.2 | 0.12.2 |
| github.com | nvidia_nvidia-container-toolkit | >= 0 < 1.17.8 | 1.17.8 |
| msrc | azl3_nvidia-container-toolkit_1.15.0-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_nvidia-container-toolkit_1.11.0-1_on_cbl_mariner_2.0 | — | — |
| nvidia | container_toolkit | — | — |
| nvidia | container_toolkit | — | — |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_msrc9.0CRITICAL
vendor_redhat9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path in github.com/NVIDIA/gpu-operator
osv·2025-10-23
CVE-2025-23266 NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path in github.com/NVIDIA/gpu-operator
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path in github.com/NVIDIA/gpu-operator
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path in github.com/NVIDIA/gpu-operator.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/NVIDIA/gpu-operator before v25.3.2.
OSV
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
osv·2025-07-17
CVE-2025-23266 [CRITICAL] NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
GHSA
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
ghsa·2025-07-17
CVE-2025-23266 [CRITICAL] CWE-426 NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
Red Hat
nvidia-container-toolkit: Privilege Escalation via Hook Initialization in NVIDIA Container Toolkit
vendor_redhat·2025-07-17·CVSS 9.0
CVE-2025-23266 [CRITICAL] CWE-426 nvidia-container-toolkit: Privilege Escalation via Hook Initialization in NVIDIA Container Toolkit
nvidia-container-toolkit: Privilege Escalation via Hook Initialization in NVIDIA Container Toolkit
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
A flaw was found in the NVIDIA Container Toolkit. This vulnerability allows execution of arbitrary code with elevated permissions via improperly secured container initialization hooks. This can potentially lead to privilege escalation, data tampering, information disclosure, and denial of service.
Statement: RHEL AI is not affected because it uses CDI mode wit
Microsoft
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successf
vendor_msrc·2025-07-08·CVSS 9.0
CVE-2025-23266 [CRITICAL] CWE-426 NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successf
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishin
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-23266 golang-github-nvidia-container-toolkit: Privilege Escalation via Hook Initialization in NVIDIA Container Toolkit [fedora-42]
bugzilla·2025-07-18·CVSS 9.0
CVE-2025-23266 [CRITICAL] CVE-2025-23266 golang-github-nvidia-container-toolkit: Privilege Escalation via Hook Initialization in NVIDIA Container Toolkit [fedora-42]
CVE-2025-23266 golang-github-nvidia-container-toolkit: Privilege Escalation via Hook Initialization in NVIDIA Container Toolkit [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on
Bugzilla
CVE-2025-23266 nvidia-container-toolkit: Privilege Escalation via Hook Initialization in NVIDIA Container Toolkit
bugzilla·2025-07-17·CVSS 9.0
CVE-2025-23266 [CRITICAL] CVE-2025-23266 nvidia-container-toolkit: Privilege Escalation via Hook Initialization in NVIDIA Container Toolkit
CVE-2025-23266 nvidia-container-toolkit: Privilege Escalation via Hook Initialization in NVIDIA Container Toolkit
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:13673 https://access.redhat.com/errata/RHSA-2025:13673
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:13674 https://access.redhat.com/errata/RHSA-2025:13674
Wiz
What Is AI Threat Intelligence? Real Risks to AI Systems Explained | Wiz
blogs_wiz·2025-12-23
What Is AI Threat Intelligence? Real Risks to AI Systems Explained | Wiz
## What is AI threat intelligence?
AI threat intelligence is the practice of understanding, tracking, and operationalizing threats that target AI systems – along with using advanced analytics to scale how that intelligence is produced and applied. At its core, it focuses on how attackers abuse, compromise, or exploit AI models, data pipelines, and the cloud infrastructure that supports them.
This distinguishes AI threat intelligence from adjacent disciplines like threat detection or SOC automation . While detection focuses on identifying suspicious activity as it occurs, threat intelligence is concerned with patterns, techniques, and trends – how threats evolve over time, which systems they target, and what conditions make those attacks viable in real environments.
AI systems require th
Wiz
What Is AI Threat Intelligence? Real Risks to AI Systems Explained | Wiz
blogs_wiz·2025-12-23
What Is AI Threat Intelligence? Real Risks to AI Systems Explained | Wiz
## What is AI threat intelligence?
AI threat intelligence is the practice of understanding, tracking, and operationalizing threats that target AI systems – along with using advanced analytics to scale how that intelligence is produced and applied. At its core, it focuses on how attackers abuse, compromise, or exploit AI models, data pipelines, and the cloud infrastructure that supports them.
This distinguishes AI threat intelligence from adjacent disciplines like threat detection or SOC automation. While detection focuses on identifying suspicious activity as it occurs, threat intelligence is concerned with patterns, techniques, and trends – how threats evolve over time, which systems they target, and what conditions make those attacks viable in real environments.
AI systems require thi
Wiz
AI Cyberattacks: How attackers target AI, and use AI against you | Wiz
blogs_wiz·2025-11-14
AI Cyberattacks: How attackers target AI, and use AI against you | Wiz
## What are AI cyberattacks?
AI cyberattacks are threats that either target AI systems – models, pipelines, agents, APIs, and the sensitive data behind them – or use AI to enhance or automate traditional attack techniques .
These attacks differ from traditional cyber threats in scale and autonomy. Attackers can now automate reconnaissance, generate exploits, bypass safety guardrails, manipulate AI agents, or poison training data across distributed cloud environments. Wiz Research has highlighted this shift across multiple investigations, including its AI attack surface mapping and its analysis of insecure vibe-generated app code .
Wiz has also demonstrated how the AI ecosystem introduces new patterns of exposure , including:
widespread AI secret leakage across GitHub in the Forbes AI 5
Wiz
AI Cyberattacks: How attackers target AI, and use AI against you | Wiz
blogs_wiz·2025-11-14
AI Cyberattacks: How attackers target AI, and use AI against you | Wiz
## What are AI cyberattacks?
AI cyberattacks are threats that either target AI systems – models, pipelines, agents, APIs, and the sensitive data behind them – or use AI to enhance or automate traditional attack techniques.
These attacks differ from traditional cyber threats in scale and autonomy. Attackers can now automate reconnaissance, generate exploits, bypass safety guardrails, manipulate AI agents, or poison training data across distributed cloud environments. Wiz Research has highlighted this shift across multiple investigations, including its AI attack surface mapping and its analysis of insecure vibe-generated app code.
Wiz has also demonstrated how the AI ecosystem introduces new patterns of exposure, including:
- widespread AI secret leakage across GitHub in the Forbes AI 50
Wiz
Crying Out Cloud Newsletter - August 2025 | Wiz
blogs_wiz·2025-08-10·CVSS 9.0
[CRITICAL] Crying Out Cloud Newsletter - August 2025 | Wiz
Welcome back! This month we’ve seen a lot of action, with both vulnerabilities and security incidents that have left users affected. We bring you the latest cloud security highlights, to help you stay informed and stay secure. Let's dive in.
## 🔍 Highlights
## Soco404 Cryptomining Campaign Exploits PostgreSQL and Cloud Misconfigurations
Wiz Research has uncovered the Soco404 campaign. A sophisticated, multi-platform cryptomining operation targeting cloud environments through exposed PostgreSQL instances, vulnerable Apache Tomcat servers, and other misconfigurations. The campaign delivers Linux and Windows payloads via fake 404 error pages embedded with base64 malware hosted on compromised or deceptive websites, including Google Sites and fraudulent crypto platforms. The attackers use a
Wiz
Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover | Wiz Blog
blogs_wiz·2025-08-04·CVSS 9.0
[CRITICAL] Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover | Wiz Blog
The Wiz Research team has discovered a chain of critical vulnerabilities in NVIDIA's Triton Inference Server, a popular open-source platform for running AI models at scale. When chained together, these flaws can potentially allow a remote, unauthenticated attacker to gain complete control of the server, achieving remote code execution (RCE).
This attack path originates in the server's Python backend and starts with a minor information leak that cleverly escalates into a full system compromise. This poses a critical risk to organizations using Triton for AI/ML, as a successful attack could lead to the theft of valuable AI models, exposure of sensitive data, manipulating the AI model's responses and a foothold for attackers to move deeper into a network.
Wiz Research responsibly disclosed
Wiz
Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover | Wiz Blog
blogs_wiz·2025-08-04·CVSS 9.0
CVE-2025-23319 [CRITICAL] Breaking NVIDIA Triton: CVE-2025-23319 - A Vulnerability Chain Leading to AI Server Takeover | Wiz Blog
The Wiz Research team has discovered a chain of critical vulnerabilities in NVIDIA's Triton Inference Server, a popular open-source platform for running AI models at scale. When chained together, these flaws can potentially allow a remote, unauthenticated attacker to gain complete control of the server, achieving remote code execution (RCE).
This attack path originates in the server's Python backend and starts with a minor information leak that cleverly escalates into a full system compromise. This poses a critical risk to organizations using Triton for AI/ML, as a successful attack could lead to the theft of valuable AI models, exposure of sensitive data, manipulating the AI model's responses and a foothold for attackers to move deeper into a network.
Wiz Research responsibly disclosed
Wiz
NVIDIAScape - NVIDIA AI Vulnerability (CVE-2025-23266) | Wiz Blog
blogs_wiz·2025-07-17·CVSS 9.0
CVE-2025-23266 [CRITICAL] NVIDIAScape - NVIDIA AI Vulnerability (CVE-2025-23266) | Wiz Blog
## Executive Summary
Wiz Research discovered a critical container escape vulnerability in the NVIDIA Container Toolkit (NCT), which we've dubbed #NVIDIAScape . This toolkit powers many AI services offered by cloud and SaaS providers, and the vulnerability, now tracked as CVE-2025-23266 , has been assigned a CVSS score of 9.0 (Critical) . It allows a malicious container to bypass isolation measures and gain full root access to the host machine. This flaw stems from a subtle misconfiguration in how the toolkit handles OCI hooks, and it can be exploited with a stunningly simple three-line Dockerfile.
Because the NVIDIA Container Toolkit is the backbone for many managed AI and GPU services across all major cloud providers, this vulnerability represents a systemic risk to the AI ecosystem, po
Wiz
NVIDIAScape - NVIDIA AI Vulnerability (CVE-2025-23266) | Wiz Blog
blogs_wiz·2025-07-17·CVSS 9.0
CVE-2025-23266 [CRITICAL] NVIDIAScape - NVIDIA AI Vulnerability (CVE-2025-23266) | Wiz Blog
# Executive Summary
Wiz Research discovered a critical container escape vulnerability in the NVIDIA Container Toolkit (NCT), which we've dubbed #NVIDIAScape. This toolkit powers many AI services offered by cloud and SaaS providers, and the vulnerability, now tracked as CVE-2025-23266, has been assigned a CVSS score of 9.0 (Critical). It allows a malicious container to bypass isolation measures and gain full root access to the host machine. This flaw stems from a subtle misconfiguration in how the toolkit handles OCI hooks, and it can be exploited with a stunningly simple three-line Dockerfile.
Because the NVIDIA Container Toolkit is the backbone for many managed AI and GPU services across all major cloud providers, this vulnerability represents a systemic risk to the AI ecosystem, potent
https://nvidia.custhelp.com/app/answers/detail/a_id/5659https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266-part-2/https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266/https://news.ycombinator.com/item?id=44818412https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape
2025-07-17
Published