Untrusted Search Path in github.com/NVIDIA/gpu-operator
CVE-2025-23266
- github.com/NVIDIA/gpu-operator
- github.com/NVIDIA/nvidia-container-toolkit
Summary
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of Privilege Escalation, Data Tampering, Information Disclosure, and Denial of Service. This issue affects github.com/NVIDIA/nvidia-container-toolkit versions prior to 1.17.8, and github.com/NVIDIA/gpu-operator versions prior to 25.3.1.
- LOW
- ADJACENT_NETWORK
- HIGH
- CHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-426 - Untrusted Search Path
The application searches for critical resources using an externally-supplied search path that can point to resources that are not under the application's direct control.
References
Advisory Timeline
- Published