Container Toolkit: Container escape / host file write via symlink following
CVSS 8.5CVE-2025-23267NVIDIA / GPU stackcurated
Impact
Container escape / host file write via symlink following
Who can reach it
Any tenant with a container
What to do
Bump nvidia-container-toolkit + restart runtime; upgrade GPU Operator; evict tenants
Fleet impact
How widespread
Universal - default hook path in every install
Cost to remediate
daemon-restart to 1.17.8
Why it hits the whole fleet
Link-following (symlink) in the privileged update-ldcache hook lets a crafted image tamper with host files or DoS the node, taking down every tenant scheduled on it
References
Related entries
- Container Toolkit: Container escape to host root via TOCTOU raceCVE-2026-24260 · Container ToolkitHigh
- Container Toolkit: Container escape to host filesystem (bypass of the CVE-2024-0132 fix)CVE-2025-23359 · Container ToolkitHigh
- Container Toolkit: Unauthorized empty-file creation on the hostCVE-2024-0133 · Container ToolkitMedium
- Container Toolkit: Container escape to host filesystem via TOCTOU in the **default** configurationCVE-2024-0132 · Container ToolkitCritical
- Container Toolkit: Container escape to host root via malicious image (LD_PRELOAD in OCI hook)CVE-2025-23266 · Container ToolkitCritical
- NVIDIA Windows GPU Display Driver (nvlddmkm.sys): A local user gets elevated enough to rewrite display configurationCVE-2021-1051 · NVIDIA Windows GPU Display Driver (nvlddmkm.sys)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.