← Back to CVE List
CVE-2025-23266NVD
Vulnerability Summary
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
CVSS v3.1 Base Metrics
Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
External References
- https://nvidia.custhelp.com/app/answers/detail/a_id/5659
- https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266-part-2/
- https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266/
- https://news.ycombinator.com/item?id=44818412
- https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape