Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

Unitree Simply Turned Your Residing Room Right into a Robotic Dojo with Embodied Avatar

November 8, 2025

Galgotias College Soars to New Heights in QS World Rankings 2026 — Marking a Continued International Rise!

November 8, 2025

EB Video games Pokémon Pop-up occasion has huge opening weekend

November 8, 2025
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • Unitree Simply Turned Your Residing Room Right into a Robotic Dojo with Embodied Avatar
  • Galgotias College Soars to New Heights in QS World Rankings 2026 — Marking a Continued International Rise!
  • EB Video games Pokémon Pop-up occasion has huge opening weekend
  • AI-powered brushing meets real-time teaching
  • Share of gross sales from new-age D2C manufacturers is exploding: Zepto’s Kaivalya Vohra
  • HeroTech’s Unattainable Lightsaber with Retractable Hilt May Cross for an Precise Film Prop
  • Kingston FURY Renegade G5 PCIe 5.0 SSD now out there in huge 8TB capability
  • PizzaExpress UAE Unveils Elevated New Menu Celebrating Recent Flavours and Culinary Creativity
Saturday, November 8
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - Essential NVIDIA Container Toolkit Flaw Permits Privilege Escalation on AI Cloud Companies
Cybersecurity & Digital Rights

Essential NVIDIA Container Toolkit Flaw Permits Privilege Escalation on AI Cloud Companies

NextTechBy NextTechJuly 18, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
Essential NVIDIA Container Toolkit Flaw Permits Privilege Escalation on AI Cloud Companies
Share
Facebook Twitter LinkedIn Pinterest Email


Jul 18, 2025Ravie LakshmananCloud Safety / AI Safety

Cybersecurity researchers have disclosed a important container escape vulnerability within the NVIDIA Container Toolkit that would pose a extreme menace to managed AI cloud providers.

The vulnerability, tracked as CVE-2025-23266, carries a CVSS rating of 9.0 out of 10.0. It has been codenamed NVIDIAScape by Google-owned cloud safety firm Wiz.

“NVIDIA Container Toolkit for all platforms incorporates a vulnerability in some hooks used to initialize the container, the place an attacker may execute arbitrary code with elevated permissions,” NVIDIA mentioned in an advisory for the bug.

Cybersecurity

“A profitable exploit of this vulnerability would possibly result in escalation of privileges, information tampering, info disclosure, and denial-of-service.”

The shortcoming impacts all variations of NVIDIA Container Toolkit as much as and together with 1.17.7 and NVIDIA GPU Operator as much as and together with 25.3.0. It has been addressed by the GPU maker in variations 1.17.8 and 25.3.1, respectively.

The NVIDIA Container Toolkit refers to a set of libraries and utilities that allow customers to construct and run GPU-accelerated Docker containers. The NVIDIA GPU Operator is designed to deploy these containers mechanically on GPU nodes in a Kubernetes cluster.

Wiz, which shared particulars of the flaw in a Thursday evaluation, mentioned the shortcoming impacts 37% of cloud environments, permitting an attacker to doubtlessly entry, steal, or manipulate the delicate information and proprietary fashions of all different prospects operating on the identical shared {hardware} by way of a three-line exploit.

The vulnerability stems from a misconfiguration in how the toolkit handles the Open Container Initiative (OCI) hook “createContainer.” A profitable exploit for CVE-2025-23266 can lead to an entire takeover of the server. Wiz additionally characterised the flaw as “extremely” straightforward to weaponize.

“By setting LD_PRELOAD of their Dockerfile, an attacker may instruct the nvidia-ctk hook to load a malicious library,” Wiz researchers Nir Ohfeld and Shir Tamari added.

“Making issues worse, the createContainer hook executes with its working listing set to the container’s root filesystem. This implies the malicious library will be loaded straight from the container picture with a easy path, finishing the exploit chain.”

Cybersecurity

All of this may be achieved with a “stunningly easy three-line Dockerfile” that hundreds the attacker’s shared object file right into a privileged course of, leading to a container escape.

The disclosure comes a few months after Wiz detailed a bypass for one more vulnerability in NVIDIA Container Toolkit (CVE-2024-0132, CVSS rating: 9.0 and CVE-2025-23359, CVSS rating: 8.3) that would have been abused to realize full host takeover.

“Whereas the hype round AI safety dangers tends to give attention to futuristic, AI-based assaults, ‘old-school’ infrastructure vulnerabilities within the ever-growing AI tech stack stay the instant menace that safety groups ought to prioritize,” Wiz mentioned.

“Moreover, this analysis highlights, not for the primary time, that containers usually are not a powerful safety barrier and shouldn’t be relied upon as the only technique of isolation. When designing functions, particularly for multi-tenant environments, one ought to all the time ‘assume a vulnerability’ and implement at the least one robust isolation barrier, comparable to virtualization.”

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a world community of future-focused thinkers.
Unlock tomorrow’s tendencies right this moment: learn extra, subscribe to our publication, and turn into a part of the NextTech neighborhood at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

Samsung Zero-Click on Flaw Exploited to Deploy LANDFALL Android Adware by way of WhatsApp

November 7, 2025

Can you notice a spy posing as a job seeker?

November 7, 2025

Hackers goal therapeutic massage parlour purchasers in blackmail scheme

November 6, 2025
Add A Comment
Leave A Reply Cancel Reply

Economy News

Unitree Simply Turned Your Residing Room Right into a Robotic Dojo with Embodied Avatar

By NextTechNovember 8, 2025

Unitree, a robotic producer based mostly in Hangzhou, launched a brand new video yesterday exhibiting…

Galgotias College Soars to New Heights in QS World Rankings 2026 — Marking a Continued International Rise!

November 8, 2025

EB Video games Pokémon Pop-up occasion has huge opening weekend

November 8, 2025
Top Trending

Unitree Simply Turned Your Residing Room Right into a Robotic Dojo with Embodied Avatar

By NextTechNovember 8, 2025

Unitree, a robotic producer based mostly in Hangzhou, launched a brand new…

Galgotias College Soars to New Heights in QS World Rankings 2026 — Marking a Continued International Rise!

By NextTechNovember 8, 2025

Better Noida, seventh November 2025: Galgotias College continues its outstanding trajectory in international…

EB Video games Pokémon Pop-up occasion has huge opening weekend

By NextTechNovember 8, 2025

Greater than 500 followers reportedly lined as much as be a part…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!