CVE-2025-23359: Nvidia-container-toolkit: GPU Container Escape (CVE-2024-0132 fix bypass)
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23359?
CVE-2025-23359 has a severity rating that indicates it poses a serious risk as it could lead to unauthorized access to the host file system.
How do I fix CVE-2025-23359?
To mitigate CVE-2025-23359, configure the NVIDIA Container Toolkit properly to prevent unauthorized access to the host file system.
What types of attacks are possible with CVE-2025-23359?
Exploitation of CVE-2025-23359 can result in code execution and potential denial of service attacks.
Which software is affected by CVE-2025-23359?
CVE-2025-23359 specifically affects the NVIDIA Container Toolkit on Linux.
What is a Time-of-Check Time-of-Use (TOCTOU) vulnerability in CVE-2025-23359?
The TOCTOU vulnerability in CVE-2025-23359 allows a crafted container image to exploit timing issues to access the host file system.