{"id":"CVE-2025-23267","aliases":["GO-2025-3998"],"url":"https://o3.security/vulnerability/CVE-2025-23267","summary":"NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook","details":"NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.","published":"2025-07-17T21:32:15Z","modified":"2025-11-05T20:32:01Z","cvss":{"score":8.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/NVIDIA/nvidia-container-toolkit","fixedVersion":"1.17.8"},{"ecosystem":"Go","name":"github.com/NVIDIA/k8s-device-plugin","fixedVersion":"0.17.3"},{"ecosystem":"Go","name":"github.com/NVIDIA/gpu-operator","fixedVersion":"25.3.2"},{"ecosystem":"Go","name":"github.com/NVIDIA/mig-parted","fixedVersion":"0.12.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-23267"},{"type":"WEB","url":"https://github.com/NVIDIA/gpu-operator"},{"type":"WEB","url":"https://github.com/NVIDIA/k8s-device-plugin"},{"type":"WEB","url":"https://github.com/NVIDIA/mig-parted"},{"type":"WEB","url":"https://github.com/NVIDIA/nvidia-container-toolkit"},{"type":"WEB","url":"https://nvidia.custhelp.com/app/answers/detail/a_id/5659"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2025-3998"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/07/16/3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-11-05T20:32:01Z"}}