NVIDIA has released an important security updatedesigned to address a critical vulnerability in the NVIDIA Container Toolkit and NVIDIA GPU Operatorthat could allow attackers to execute arbitrary code, gain elevated privileges, and access the host file system.
See also: NVIDIA UFM vulnerability allows hackers to escalate privileges

The vulnerability, known as CVE-2025-23359 , is classified as a Time-of-Check to Time-of-Use (TOCTOU) error and has been assessed with a CVSS v3.1 baseline score of 8.3 , classified as “ High ”.
The vulnerability is found in the default configuration of the NVIDIA Container Toolkit in a Linux.
A maliciously crafted container image can exploit a race condition, gaining unauthorized access to the host's file system. Successful exploitation of this vulnerability could lead to:
- Εκτέλεση αυθαίρετων εντολών στον κεντρικό υπολογιστή.
- Απόκτηση αυξημένων προνομίων.
- System shutdown.
- Exposure of sensitive data.
- Unauthorized file modification.
See also: Fugatto: NVIDIA's AI model changes what we know about sound
This vulnerability affects all versions of the NVIDIA Container Toolkit up to version 1.17.3, as well as NVIDIA GPU Operator up to version 24.9.1.

NVIDIA acknowledges Wiz Research researchers Andres Riancho , Ronen Shustin, Shir Tamari , and Lei Wang for discovering this vulnerability, expressing its appreciation for their contributions.
NVIDIA recommends that users proceed with the installation of the following updates:

Recent updates modify the default behavior of the NVIDIA Container Toolkit, as it no longer automatically places CUDA compatibility libraries from the /usr/local/cuda/compat into containers.
See also: NVIDIA Base Command Manager vulnerability allows remote code execution
An arbitrary code execution vulnerability refers to a serious security flaw in a system or application that allows an attacker to execute arbitrary code. It typically occurs due to flaws in the way the software processes input data, such as buffer overflows or unsafe parsing operations. Such an exploitation can lead to loss of control of the system, data theft, or even complete takeover. It is critical to protect against such vulnerabilities by regularly updating software and adopting safe programming practices.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
