Critical NVIDIA Container Toolkit Flaw Allows Privilege Escalation on AI Cloud Services

Threat Score
69%
5 articles 100.0% Similarity 1 day ago

Activity Timeline

CVE-2025-23267:A vulnerability in NVIDIA Container...
OSS Security
Jul 16
11:40
NVIDIA Container Toolkit Vulnerability Allows Priv...
GB Hackers
Jul 17
11:20
NVIDIA Container Toolkit Vulnerability Allows Elev...
Cybersecurity News
Jul 17
12:58
Critical Nvidia Toolkit Flaw Exposes AI Cloud Serv...
SecurityWeek
Jul 18
08:42
Critical NVIDIA Container Toolkit Flaw Allows Priv...
The Hacker News
Primary Article
Jul 18
10:59
Cybersecurity researchers have disclosed a critical container escape vulnerability in theNVIDIA Container Toolkitthat could pose a severe threat to managed AI cloud services. The vulnerability, tracked as CVE-2025-23266, carries a CVSS score of 9.0 out of 10.0. It has been codenamedNVIDIAScapeby Google-owned cloud security company Wiz. "NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions," NVIDIAsaidin an advisory for the bug. "A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial-of-service." The shortcoming impacts all versions of NVIDIA Container Toolkit up to and including 1.17.7 and NVIDIA GPU Operator up to and including 25.3.0. It has been addressed by the GPU maker in versions 1.17.8 and 25.3.1, respectively. The NVIDIA Container Toolkit refers to a collection of l...

Cluster AI

Beta Organization

Save to Folder

Choose a folder to save this cluster: