CVE-2025-23359: NVIDIA Container Toolkit

High severity, CVSS 8.1. EPSS: 3.7% chance of exploitation in the next 30 days.

NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Affected products

  • NVIDIA NVIDIA Container Toolkit: before 1.17.4 (fixed in 1.17.4)
  • NVIDIA NVIDIA GPU Operator: before 24.9.2 (fixed in 24.9.2)

Published 2025-02-12. Last modified 2026-06-17.