CVE-2025-23359 is a Time-of-Check Time-of-Use (TOCTOU) vulnerability in the NVIDIA Container Toolkit for Linux, affecting various NVIDIA and Linux kernel products. This high-severity flaw (CVSS 8.1) allows a crafted container image to gain host file system access, potentially leading to code execution, denial of service, privilege escalation, information disclosure, and data tampering. While the attack complexity is high, no user interaction is required. Currently, there is no evidence of active exploitation, nor are there public exploit modules like Metasploit or Nuclei, though it has garnered some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.4CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:* | ||
< 24.9.2CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
nvidia-container-toolkit: TOCTOU Vulnerability in NVIDIA Container Toolkit
Feb 12, 2025NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Feb 11, 2025