CVE-2025-23266

EUVD-2025-21811
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9 CRITICAL
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
toolbox
RHEL 9
0:0.2-1.el9_6
fixed
toolbox-tests
RHEL 9
0:0.2-1.el9_6
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
nvidia-container-toolkit
Azure Linux 3.0
0:1.17.8-1.azl3
fixed
CBL-Mariner 2.0
0:1.17.8-1.cm2
fixed