CVE-2025-23267
published 2025-07-17CVE-2025-23267: NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a…
PriorityP348high8.5CVSS 3.1
AVNACLPRLUINSCCNILAH
EPSS
0.68%
48.0th percentile
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | nvidia_gpu-operator | >= 0 < 25.3.2 | 25.3.2 |
| github.com | nvidia_k8s-device-plugin | >= 0 < 0.17.3 | 0.17.3 |
| github.com | nvidia_mig-parted | >= 0 < 0.12.2 | 0.12.2 |
| github.com | nvidia_nvidia-container-toolkit | >= 0 < 1.17.8 | 1.17.8 |
| nvidia | container_toolkit | — | — |
| nvidia | container_toolkit | — | — |
CVSS provenance
nvdv3.18.5HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook in github.com/NVIDIA/gpu-operator
osv·2025-10-23
CVE-2025-23267 NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook in github.com/NVIDIA/gpu-operator
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook in github.com/NVIDIA/gpu-operator
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook in github.com/NVIDIA/gpu-operator.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/NVIDIA/gpu-operator before v25.3.2.
OSV
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook
osv·2025-07-17
CVE-2025-23267 [HIGH] NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.
GHSA
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook
ghsa·2025-07-17
CVE-2025-23267 [HIGH] CWE-59 NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.
Red Hat
nvidia-container-toolkit: NVIDIA Container Toolkit Link Following Vulnerability
vendor_redhat·2025-07-17·CVSS 8.5
CVE-2025-23267 [HIGH] CWE-59 nvidia-container-toolkit: NVIDIA Container Toolkit Link Following Vulnerability
nvidia-container-toolkit: NVIDIA Container Toolkit Link Following Vulnerability
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.
A flaw was found in nvidia-container-toolkit. The `update-ldcache` hook contains a vulnerability allowing an attacker to trigger link following via a specially crafted container image. This issue allows a local attacker to potentially cause data corruption. The root cause is the improper handling of container image paths during the link cache update process, which may result in data loss.
Statement: RHEL AI is not affected becaus
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-23267 golang-github-nvidia-container-toolkit: NVIDIA Container Toolkit Link Following Vulnerability [fedora-42]
bugzilla·2025-07-18·CVSS 8.5
CVE-2025-23267 [HIGH] CVE-2025-23267 golang-github-nvidia-container-toolkit: NVIDIA Container Toolkit Link Following Vulnerability [fedora-42]
CVE-2025-23267 golang-github-nvidia-container-toolkit: NVIDIA Container Toolkit Link Following Vulnerability [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is
Wiz
Crying Out Cloud Newsletter - August 2025 | Wiz
blogs_wiz·2025-08-10·CVSS 9.0
[CRITICAL] Crying Out Cloud Newsletter - August 2025 | Wiz
Welcome back! This month we’ve seen a lot of action, with both vulnerabilities and security incidents that have left users affected. We bring you the latest cloud security highlights, to help you stay informed and stay secure. Let's dive in.
## 🔍 Highlights
## Soco404 Cryptomining Campaign Exploits PostgreSQL and Cloud Misconfigurations
Wiz Research has uncovered the Soco404 campaign. A sophisticated, multi-platform cryptomining operation targeting cloud environments through exposed PostgreSQL instances, vulnerable Apache Tomcat servers, and other misconfigurations. The campaign delivers Linux and Windows payloads via fake 404 error pages embedded with base64 malware hosted on compromised or deceptive websites, including Google Sites and fraudulent crypto platforms. The attackers use a
2025-07-17
Published