logo

NVIDIAScape - Critical NVIDIA AI Vulnerability: A Three-Line Container Escape in NVIDIA Container Toolkit (CVE-2025-23266)

ID: 96f8f85c-86ea-542e-a467-3f4f5cb73338

STIX ID: report--96f8f85c-86ea-542e-a467-3f4f5cb73338

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2025-07-17

Date Updated: 2026-05-01

...
...

**Wiz Research disclosed CVE-2025-23266, a critical (CVSS 9.0) container escape in the NVIDIA Container Toolkit that allows a malicious container to bypass isolation and gain root on the host by abusing OCI createContainer hooks and LD_PRELOAD; the report includes a three-line Dockerfile PoC, impact analysis across multi-tenant GPU/cloud services, and recommended mitigations (upgrade to patched toolkit versions or disable the enable-cuda-compat hook).**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.