NVIDIA Container Toolkit是美国英伟达(NVIDIA)公司的一个容器工具包。允许用户构建和运行 GPU 加速的容器。 NVIDIA Container Toolkit存在代码问题漏洞,该漏洞源于容器初始化钩子缺陷,可能导致权限提升、数据篡改、信息泄露和拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NVIDIA | Container Toolkit | NVIDIA Container Toolkit All versions up to and including 1.17.7 (CDI mode only for versions prior to 1.17.5) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/jpts/cve-2025-23266-poc | POC Details |
| 2 | CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit | https://github.com/r0binak/CVE-2025-23266 | POC Details |
| 3 | cve-2025-23266-migration-bypass | https://github.com/Mindasy/cve-2025-23266-migration-bypass | POC Details |
| 4 | None | https://github.com/mrk336/CVE-2025-23266 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-23267 | 8.5 HIGH | NVIDIA Container Toolkit 后置链接漏洞 |
| CVE-2025-23263 | 7.6 HIGH | NVIDIA DOCA-Host和NVIDIA Mellanox OFED 安全漏洞 |
| CVE-2025-23270 | 7.1 HIGH | NVIDIA Jetson Linux 安全漏洞 |
| CVE-2025-23269 | 4.7 MEDIUM | NVIDIA Jetson Linux 安全漏洞 |
No comments yet