# CVE-2025-23266

## Summary

- **CVE ID:** CVE-2025-23266
- **Severity:** CRITICAL
- **CVSS Score:** 9 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-426
- **Published:** Jul 17, 2025
- **Last Modified:** Mar 13, 2026

## Description

NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.

## Affected Products

- NVIDIA — Container Toolkit (NVIDIA Container Toolkit All versions up to and including 1.17.7 (CDI mode only for versions prior to 1.17.5))
- NVIDIA — Container Toolkit (NVIDIA GPU Operator All versions up to and including 25.3.0 (CDI mode only for versions prior to 25.3.0))

## References

- [CNA](https://nvidia.custhelp.com/app/answers/detail/a_id/5659)
- [CVE](https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266/)
- [CVE](https://news.ycombinator.com/item?id=44818412)
- [CVE](https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape)
- [CVE](https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266-part-2/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 3.11%
- **EPSS Percentile:** 87.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._