Описание
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-23267
- https://github.com/NVIDIA/gpu-operator
- https://github.com/NVIDIA/k8s-device-plugin
- https://github.com/NVIDIA/mig-parted
- https://github.com/NVIDIA/nvidia-container-toolkit
- https://nvidia.custhelp.com/app/answers/detail/a_id/5659
- https://pkg.go.dev/vuln/GO-2025-3998
- http://www.openwall.com/lists/oss-security/2025/07/16/3
Пакеты
github.com/NVIDIA/nvidia-container-toolkit
< 1.17.8
1.17.8
github.com/NVIDIA/k8s-device-plugin
< 0.17.3
0.17.3
github.com/NVIDIA/gpu-operator
< 25.3.2
25.3.2
github.com/NVIDIA/mig-parted
< 0.12.2
0.12.2
Связанные уязвимости
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.
Уязвимость функции update-ldcache программного обеспечения для создания и запуска контейнеров NVIDIA Container Toolkit и программного средства для управления ресурсами NVIDIA GPU Operator, позволяющая нарушителю получить несанкционированный доступ на изменение защищаемой информации или вызвать отказ в обслуживании