Описание
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-23266
- https://github.com/NVIDIA/gpu-operator
- https://github.com/NVIDIA/k8s-device-plugin
- https://github.com/NVIDIA/mig-parted
- https://github.com/NVIDIA/nvidia-container-toolkit
- https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266
- https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266-part-2
- https://news.ycombinator.com/item?id=44818412
- https://nvidia.custhelp.com/app/answers/detail/a_id/5659
- https://pkg.go.dev/vuln/GO-2025-3992
- https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape
Пакеты
github.com/NVIDIA/nvidia-container-toolkit
< 1.17.8
1.17.8
github.com/NVIDIA/k8s-device-plugin
< 0.17.3
0.17.3
github.com/NVIDIA/gpu-operator
< 25.3.2
25.3.2
github.com/NVIDIA/mig-parted
< 0.12.2
0.12.2
Связанные уязвимости
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
Уязвимость функции enable-cuda-compat программного обеспечения для создания и запуска контейнеров NVIDIA Container Toolkit и программного средства для управления ресурсами NVIDIA GPU Operator, позволяющая нарушителю выполнить произвольный код, повысить свои привилегии, получить несанкционированный доступ на чтение и изменение защищаемой информации или вызвать отказ в обслуживании