VYPR
High severity8.5NVD Advisory· Published Jul 17, 2025· Updated Apr 15, 2026

CVE-2025-23267

CVE-2025-23267

Description

NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/NVIDIA/nvidia-container-toolkitGo
< 1.17.81.17.8
github.com/NVIDIA/k8s-device-pluginGo
< 0.17.30.17.3
github.com/NVIDIA/gpu-operatorGo
< 25.3.225.3.2
github.com/NVIDIA/mig-partedGo
< 0.12.20.12.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.