Vulnerability Description
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://nvidia.custhelp.com/app/answers/detail/a_id/5659
- https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266-part-2/
- https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266/
- https://news.ycombinator.com/item?id=44818412
- https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape
FAQ
What is CVE-2025-23266?
CVE-2025-23266 is a vulnerability with a CVSS score of 9.0 (CRITICAL). NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successf...
How severe is CVE-2025-23266?
CVE-2025-23266 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-23266?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.