PT-2025-40051 · Go · Github.Com/Nvidia/Gpu-Operator+3

Published

2025-07-17

·

Updated

2025-07-17

CVSS v3.1

9.0

Critical

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-VMG3-7V43-9G23

Affected Products

Github.Com/Nvidia/Gpu-Operator
Github.Com/Nvidia/K8S-Device-Plugin
Github.Com/Nvidia/Mig-Parted
Github.Com/Nvidia/Nvidia-Container-Toolkit