CVE-2025-23359
published 2025-02-12CVE-2025-23359: NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container…
PriorityP351high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
3.58%
88.0th percentile
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | azl3_nvidia-container-toolkit_1.17.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_nvidia-container-toolkit_1.17.4-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_nvidia-container-toolkit_1.17.3-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nvidia-container-toolkit_1.17.4-1_on_cbl_mariner_2.0 | — | — |
| nvidia | container_toolkit | — | — |
| nvidia | gpu_operator | — | — |
| nvidia | nvidia_container_toolkit | < 1.17.4 | 1.17.4 |
| nvidia | nvidia_gpu_operator | < 24.9.2 | 24.9.2 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.0CRITICAL
vendor_msrc8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4hmh-pm5p-9j7j: NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted c
ghsa_unreviewed·2025-02-12
CVE-2025-23359 [HIGH] CWE-367 GHSA-4hmh-pm5p-9j7j: NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted c
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Red Hat
nvidia-container-toolkit: TOCTOU Vulnerability in NVIDIA Container Toolkit
vendor_redhat·2025-02-12·CVSS 8.3
CVE-2025-23359 [HIGH] CWE-367 nvidia-container-toolkit: TOCTOU Vulnerability in NVIDIA Container Toolkit
nvidia-container-toolkit: TOCTOU Vulnerability in NVIDIA Container Toolkit
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
A flaw was found in the NVIDIA Container Toolkit for Linux. This vulnerability allows a crafted container image to gain access to the host file system via a Time-of-Check Time-of-Use (TOCTOU) flaw in the default configuration, potentially leading to code execution, denial of service, escalation of privileges, information disclosure, and data tampering
Microsoft
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file
vendor_msrc·2025-02-11·CVSS 8.3
CVE-2025-23359 [HIGH] CWE-367 NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this wo
Red Hat
nvidia-container-toolkit: Time-of-check Time-of-use (TOCTOU) Race Condition in NVIDIA Container toolkit
vendor_redhat·2024-09-26·CVSS 9.0
CVE-2024-0132 [CRITICAL] CWE-367 nvidia-container-toolkit: Time-of-check Time-of-use (TOCTOU) Race Condition in NVIDIA Container toolkit
nvidia-container-toolkit: Time-of-check Time-of-use (TOCTOU) Race Condition in NVIDIA Container toolkit
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
A flaw was found in the NVIDIA Container Toolkit. Affected versions contain a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with the default configuration, where a specifically crafted container image may gain access to the host file system. Thi
No detection rules found.
No public exploits indexed.
Wiz
What is Container Vulnerability Management? | Wiz
blogs_wiz·2025-05-22·CVSS 8.3
[HIGH] What is Container Vulnerability Management? | Wiz
Container vulnerability management tracks and fixes flaws in every part of the container stack—from build system and image registry, through the orchestrator’s admission controllers, down to the host kernel interfaces—by scanning base images, libraries, and runtime settings before they cause issues
Containers bring huge benefits, such as isolated workloads, easy scaling, and portability. But they also present unique challenges: They appear and vanish in seconds, and they inherit many nested layers and can drift from your intended state. As a result, one‑time scans are useless. What you scanned yesterday may be gone in an hour, replaced by a mutated instance with new risks. You need continuous scanning built into your pipeline to track CVEs , catch risky modules, and check for overly broad
Wiz
What is Container Vulnerability Management? | Wiz
blogs_wiz·2025-05-22
What is Container Vulnerability Management? | Wiz
Container vulnerability management tracks and fixes flaws in every part of the container stack—from build system and image registry, through the orchestrator’s admission controllers, down to the host kernel interfaces—by scanning base images, libraries, and runtime settings before they cause issues
Containers bring huge benefits, such as isolated workloads, easy scaling, and portability. But they also present unique challenges: They appear and vanish in seconds, and they inherit many nested layers and can drift from your intended state. As a result, one‑time scans are useless. What you scanned yesterday may be gone in an hour, replaced by a mutated instance with new risks. You need continuous scanning built into your pipeline to track CVEs, catch risky modules, and check for overly broad
Trendmicro
Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
blogs_trendmicro·2025-04-10·CVSS 9.0
CVE-2024-0132 [CRITICAL] Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
Exploits & Vulnerabilities
# Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
A previously disclosed vulnerability in NVIDIA Container Toolkit has an incomplete patch, which, if exploited, could put a wide range of AI infrastructure and sensitive data at risk.
By: Abdelrahman Esmail
2025/04/10
Read time: ( words)
Save to Folio
Summary:
- Trend Research identified that NVIDIA’s September 2024 security update for a critical vulnerability (CVE-2024-0132) in the NVIDIA Container Toolkit was incomplete, leaving systems potentially vulnerable to container escape attacks. Additionally, researchers discovered a denial-of-service (DoS) vulnerability affecting Docker on Linux.
- Exploiting these vulnerabilities could enable attackers to access sens
Wiz
NVIDIA AI vulnerability: Deep Dive into CVE 2024-0132 | Wiz Blog
blogs_wiz·2025-02-11·CVSS 9.0
CVE-2024-0132 [CRITICAL] NVIDIA AI vulnerability: Deep Dive into CVE 2024-0132 | Wiz Blog
# Executive summary
In September of last year, Wiz Research uncovered a critical security vulnerability, tracked as CVE-2024-0132, in the widely used NVIDIA Container Toolkit, which provides containerized AI applications with access to GPU resources. Our initial blog post was purposely vague because the vulnerability was under embargo for an extended period, allowing both NVIDIA and cloud providers to address the issue. As we detailed in our initial blog post, this vulnerability affects any AI application—whether in the cloud or on-premises—that is running the vulnerable container toolkit. Today, we are ready to release the technical details of the vulnerability.
The vulnerability enables attackers who control a container image executed by the vulnerable toolkit to escape from the contai
Wiz
NVIDIA AI vulnerability: Deep Dive into CVE 2024-0132 | Wiz Blog
blogs_wiz·2025-02-11·CVSS 9.0
CVE-2024-0132 [CRITICAL] NVIDIA AI vulnerability: Deep Dive into CVE 2024-0132 | Wiz Blog
## Executive summary
In September of last year, Wiz Research uncovered a critical security vulnerability, tracked as CVE-2024-0132, in the widely used NVIDIA Container Toolkit, which provides containerized AI applications with access to GPU resources. Our initial blog post was purposely vague because the vulnerability was under embargo for an extended period, allowing both NVIDIA and cloud providers to address the issue. As we detailed in our initial blog post, this vulnerability affects any AI application—whether in the cloud or on-premises—that is running the vulnerable container toolkit. Today, we are ready to release the technical details of the vulnerability.
The vulnerability enables attackers who control a container image executed by the vulnerable toolkit to escape from the conta
2025-02-12
Published