PT-2025-6424 · Nvidia · Nvidia Container Toolkit
Andres Riancho
+4
·
Published
2025-02-11
·
Updated
2025-07-16
·
CVE-2025-23359
8.3
High
Base vector | Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
NVIDIA Container Toolkit versions up to and including 1.17.3
NVIDIA GPU Operator versions up to and including 24.9.1
**Description:**
NVIDIA Container Toolkit and NVIDIA GPU Operator are affected by a Time-of-Check Time-of-Use (TOCTOU) vulnerability. This flaw can allow a crafted container image to gain access to the host file system, potentially leading to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. A bypass was discovered for a previously patched security flaw, reflagged as CVE-2025-23359. The vulnerability exists due to errors in synchronization when using a shared resource, creating a race condition.
**Recommendations:**
NVIDIA Container Toolkit versions up to and including 1.17.3: Upgrade to a newer version to address the vulnerability.
NVIDIA GPU Operator versions up to and including 24.9.1: Upgrade to a newer version to address the vulnerability.
Exploit
Fix
LPE
DoS
Time Of Check To Time Of Use
Weakness Enumeration
Related Identifiers
Affected Products
References · 48
- 🔥 https://thehackernews.com/2025/04/incomplete-patch-in-nvidia-toolkit.html · Exploit
- https://zerodayinitiative.com/advisories/ZDI-25-087 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-23359 · Security Note
- https://bdu.fstec.ru/vul/2025-02018 · Security Note
- https://twitter.com/TheZDIBugs/status/1894152192564609195 · Twitter Post
- https://twitter.com/mkan0x/status/1910382688152019108 · Twitter Post
- https://twitter.com/CCBalert/status/1890333577973223711 · Twitter Post
- https://twitter.com/fridaysecurity/status/1890219744399352163 · Twitter Post
- https://twitter.com/oss_security/status/1890587288846942420 · Twitter Post
- https://twitter.com/SystemTek_UK/status/1889715012077322444 · Twitter Post
- https://twitter.com/grok/status/1945292571145863319 · Twitter Post
- https://twitter.com/mkan0x/status/1910382707219046767 · Twitter Post
- https://twitter.com/IseleyeNimi/status/1892269750031442163 · Twitter Post
- https://twitter.com/byt3n33dl3/status/1910378118881435659 · Twitter Post
- https://t.me/c/1009650918/6648 · Telegram Post