Container Toolkit: Container escape to host root via malicious image (LD_PRELOAD in OCI hook)
Impact
Container escape to host root via malicious image (LD_PRELOAD in OCI hook)
Who can reach it
Any tenant that can run an arbitrary container image on a GPU node
What to do
Emergency: bump nvidia-container-toolkit to 1.17.8+, restart container runtime on every GPU node, upgrade GPU Operator Helm chart; evict and re-admit all tenant workloads; audit for prior exploitation
Fleet impact
How widespread
Very common - the standard way to ship driver + toolkit + DCGM on every K8s-based neocloud
Cost to remediate
node-drain in practice: the Operator's driver and toolkit DaemonSets restart per node, and a driver-container reload requires evicting every GPU pod
Why it hits the whole fleet
One Helm version bump has to roll across every GPU node pool; until it finishes, every tenant pod on an un-rolled node still holds the escape primitive
References
Related entries
- Container Toolkit: Container escape / host file write via symlink followingCVE-2025-23267 · Container ToolkitHigh
- Container Toolkit: Container escape to host root via TOCTOU raceCVE-2026-24260 · Container ToolkitHigh
- Container Toolkit: Container escape to host filesystem (bypass of the CVE-2024-0132 fix)CVE-2025-23359 · Container ToolkitHigh
- Container Toolkit: Unauthorized empty-file creation on the hostCVE-2024-0133 · Container ToolkitMedium
- Container Toolkit: Container escape to host filesystem via TOCTOU in the **default** configurationCVE-2024-0132 · Container ToolkitCritical
- BlueField (GA firmware): out-of-bounds write in the VF command interface allows code execution on the DPUCVE-2025-23350 · BlueField (GA firmware)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.