CVE-2025-23266
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
Vendor
-
Product
-
CWE
Yayın Tarihi
2025-07-17 20:15:28
Güncelleme
2025-08-16 22:15:25
Source Identifier
psirt@nvidia.com
KEV Date Added
-
Kategoriler
Referanslar
https://nvidia.custhelp.com/app/answers/detail/a_id/5659
https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266-part-2/
https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266/
https://news.ycombinator.com/item?id=44818412
https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape