CRITICAL9.0
GHSA-vmg3-7v43-9g23
NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path
Quick fix
GHSA-vmg3-7v43-9g23 — github.com/NVIDIA/nvidia-container-toolkit: upgrade to the fixed version with the command below.
go get github.com/NVIDIA/nvidia-container-toolkit@v1.17.8Details
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/NVIDIA/nvidia-container-toolkit
Introduced in:
0Fixed in: 1.17.8Fix
go get github.com/NVIDIA/nvidia-container-toolkit@v1.17.8Go/github.com/NVIDIA/k8s-device-plugin
Introduced in:
0Fixed in: 0.17.3Fix
go get github.com/NVIDIA/k8s-device-plugin@v0.17.3Go/github.com/NVIDIA/gpu-operator
Introduced in:
0Fixed in: 25.3.2Fix
go get github.com/NVIDIA/gpu-operator@v25.3.2Go/github.com/NVIDIA/mig-parted
Introduced in:
0Fixed in: 0.12.2Fix
go get github.com/NVIDIA/mig-parted@v0.12.2References
- https://nvd.nist.gov/vuln/detail/CVE-2025-23266[ADVISORY]
- https://github.com/NVIDIA/gpu-operator[WEB]
- https://github.com/NVIDIA/k8s-device-plugin[WEB]
- https://github.com/NVIDIA/mig-parted[WEB]
- https://github.com/NVIDIA/nvidia-container-toolkit[WEB]
- https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266[WEB]
- https://kidbomb.github.io/posts/nvidia-container-escape-cve-2025-23266-part-2[WEB]
- https://news.ycombinator.com/item?id=44818412[WEB]
- https://nvidia.custhelp.com/app/answers/detail/a_id/5659[WEB]
- https://pkg.go.dev/vuln/GO-2025-3992[WEB]
- https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape[WEB]