Container Toolkit: Container escape / host file write via symlink following
CVE-2025-23267NVIDIA / GPU stackcurated
Impact
Container escape / host file write via symlink following
Who can reach it
Any tenant with a container
What to do
Bump nvidia-container-toolkit + restart runtime; upgrade GPU Operator; evict tenants
Fleet impact
How widespread
Universal - default hook path in every install
Cost to remediate
daemon-restart to 1.17.8
Why it hits the whole fleet
Link-following (symlink) in the privileged update-ldcache hook lets a crafted image tamper with host files or DoS the node, taking down every tenant scheduled on it
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.