CVE-2025-23266
CVE-2025-23266
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
NVIDIA · Container Toolkitpublic PoCs found — 5
githubgithub.com/jpts/cve-2025-23266-poc★ 14githubgithub.com/mrk336/CVE-2025-23266★ 2githubgithub.com/r0binak/CVE-2025-23266★ 1githubgithub.com/Mindasy/cve-2025-23266-migration-bypass★ 1githubgithub.com/CR1MS0N-Operator/security-research★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266/https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266-part-2/https://news.ycombinator.com/item?id=44818412https://nvidia.custhelp.com/app/answers/detail/a_id/5659https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape