NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.
CVSS Details
- CVSS 3.1 Base Score: 9
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade toolbox-testsUpgrade toolbox | Aug 14, 2025 | Aug 12, 2025 |
| Redhat_linux | — | Upgrade toolbox-debugsourceUpgrade toolbox-debuginfoUpgrade toolboxUpgrade toolbox-tests | Jul 21, 2025 | Jul 17, 2025 |
| Rocky_linux | — | Upgrade toolbox-debuginfoUpgrade toolbox-testsUpgrade toolboxUpgrade toolbox-debugsource | Feb 16, 2026 | Oct 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub