ZDI-CAN-26525: ZDI-25-087: NVIDIA Container Toolkit mount_files Time-Of-Check Time-Of-Use Race Condition Privilege Escalation Vulnerability
This vulnerability allows remote attackers to escalate privileges on affected installations of NVIDIA Container Toolkit. An attacker must first obtain the ability to execute code within a container in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.0. The following CVEs are assigned: CVE-2025-23359.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26525?
The severity of ZDI-CAN-26525 is rated at 9.0 on the CVSS scale, indicating a high risk of exploitation.
How do I fix ZDI-CAN-26525?
To fix ZDI-CAN-26525, update your NVIDIA Container Toolkit to the latest version provided by NVIDIA.
What are the potential impacts of ZDI-CAN-26525?
ZDI-CAN-26525 allows remote attackers to escalate privileges on affected installations, potentially compromising the container's security.
Who is affected by ZDI-CAN-26525?
Anyone using the NVIDIA Container Toolkit is potentially vulnerable to ZDI-CAN-26525.
What types of attacks are possible with ZDI-CAN-26525?
ZDI-CAN-26525 allows for remote code execution and privilege escalation within containers.