ZDI-25-087: NVIDIA Container Toolkit mount_files Time-Of-Check Time-Of-Use Race Condition Privilege Escalation Vulnerability
This vulnerability allows remote attackers to escalate privileges on affected installations of NVIDIA Container Toolkit. An attacker must first obtain the ability to execute code within a container in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.0. The following CVEs are assigned: CVE-2025-23359.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-087?
The severity of ZDI-25-087 is rated at 9.0, indicating critical risk.
How do I fix ZDI-25-087?
To fix ZDI-25-087, update the NVIDIA Container Toolkit to the latest version provided by NVIDIA.
Who is affected by ZDI-25-087?
ZDI-25-087 affects installations of the NVIDIA Container Toolkit that allow code execution within containers.
What type of vulnerability is ZDI-25-087?
ZDI-25-087 is a privilege escalation vulnerability that allows remote attackers to gain elevated permissions.
Can ZDI-25-087 be exploited without access to the container?
No, an attacker must first obtain the ability to execute code within the container to exploit ZDI-25-087.