cbcvebase.
CVE-2025-23267
published 2025-07-17

CVE-2025-23267: NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a…

PriorityP348high8.5CVSS 3.1
AVNACLPRLUINSCCNILAH
EPSS
0.68%
48.0th percentile
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.

Affected

6 ranges
VendorProductVersion rangeFixed in
github.comnvidia_gpu-operator>= 0 < 25.3.225.3.2
github.comnvidia_k8s-device-plugin>= 0 < 0.17.30.17.3
github.comnvidia_mig-parted>= 0 < 0.12.20.12.2
github.comnvidia_nvidia-container-toolkit>= 0 < 1.17.81.17.8
nvidiacontainer_toolkit
nvidiacontainer_toolkit

CVSS provenance

nvdv3.18.5HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.