🔥 24×7 Proxy Interview Support · Job Support · Profile Engineering | USA • Canada • UK • Europe • Australia

Postmortem · CVE-2025-23266 · CVSS 9.0

NVIDIAScape (CVE-2025-23266) — NVIDIA Container Toolkit OCI-Hook Escape Postmortem

A single LD_PRELOAD line in a container image could run code as root on the host via a privileged NVIDIA hook. Here is the record and the fix.

Less than a year after CVE-2024-0132, the NVIDIA Container Toolkit had a second critical container-escape class — this time via an OCI hook that honoured an attacker-controlled LD_PRELOAD.

NVIDIAScape (CVE-2025-23266) was an OCI-hook environment-variable injection in the NVIDIA Container Toolkit. When a container starts under the NVIDIA runtime, the toolkit registers hooks — including a createContainer hook that runs as a privileged process on the host. By setting LD_PRELOAD in the container image to point at a malicious shared library, an attacker could have that privileged hook load and execute their code with root on the host — a clean container escape from an otherwise ordinary-looking image. It is the second critical escape in this component in under a year, underlining that the GPU runtime deserves kernel-grade version hygiene. The record and fix are below.

What We Offer

Expert Support for Every IT Challenge

From daily job support to emergency production fixes, proxy interview guidance, and interview coaching — we have the expert for your specific need.

Real-Time Kubernetes AI Job Support

Live expert help during your working hours — running LLM inference (vLLM, KServe, Dynamo), agent runtimes and sandboxes, GPU scheduling, autoscaling, RAG pipelines, and daily platform deliverables on your real cluster so you always hit your deadlines.

Production AI Incident Support

On-call firefighting for live incidents — GPU Pods stuck Pending, CUDA/OOMKilled crashes, vLLM out-of-memory, high TTFT, model-loading failures, autoscaling that will not scale, agent loops, MCP authorization errors, and RAG/vector-DB latency — with an engineer on the call.

Interview & Candidate Marketing

Kubernetes AI proxy interview assistance, profile positioning, and candidate marketing for Platform Engineer, AI Infrastructure Engineer, GPU Infrastructure Engineer, MLOps/LLMOps, and SRE roles — real-time interview guidance, recruiter readiness, and profile visibility.

Real Situations

Incident Record

These are the real-world situations our experts resolve every day — for job support and interview assistance.

DATE: Disclosed July 2025 by Wiz Research.
PLATFORM: Kubernetes and container GPU nodes using the NVIDIA Container Toolkit (notably Linux CDI mode).
COMPONENT: NVIDIA Container Toolkit ≤ 1.17.7 and NVIDIA GPU Operator ≤ 25.3.0 (Linux, CDI mode).
WHAT HAPPENED: An OCI createContainer hook ran as a privileged host process and honoured a container-controlled LD_PRELOAD, loading an attacker-supplied .so into the privileged process.
IMPACT: Container escape with root code execution on the host — full node compromise on shared GPU clusters (CVSS 9.0, Critical).
ROOT CAUSE: Untrusted search path / environment-variable injection: the privileged hook trusted LD_PRELOAD from the container environment.
MITIGATION: If you cannot patch immediately, prevent running untrusted images on GPU nodes, detect containers setting LD_PRELOAD to unusual .so paths (e.g. /proc/self/cwd/*.so), and isolate untrusted workloads with gVisor/Kata.
FIX: Upgrade NVIDIA Container Toolkit to 1.17.8 or later and NVIDIA GPU Operator to 25.3.1 or later.
OPERATIONAL LESSON: Two critical escapes in one component in a year means defence-in-depth, not just patching: least-privilege on GPU nodes, image provenance, and runtime isolation for anything untrusted.

Global Reach

Real-time Kubernetes AI infrastructure support for engineers across USA, Canada, UK, Ireland, Germany, Netherlands, Switzerland, Australia, New Zealand, Singapore, UAE, and worldwide.

Available across US, Canada, UK, European, Australian, and Asia-Pacific business hours — and 24/7 for production incidents.

In-house experts — no sub-contracting or outsourcing
24/7 availability for urgent job support and interview needs
Confidential & professional — NDA available on request
Same-day onboarding for most job support and interview cases
Combined job support + proxy interview service available

Ready to Get Expert Help? Talk to Us Now.

Join 1000+ developers who resolved their job challenges and cleared interviews with real-time expert support.

Expert Help Available

Need real-time IT job support or interview help? Our experts are available 24/7 — USA, Canada, UK, Europe & worldwide.

Get Instant HelpCall Now

FAQ

Frequently Asked Questions

Everything you need to know before getting started with job support or interview assistance.

Ask on WhatsApp

An OCI createContainer hook ran as a privileged host process and honoured a container-controlled LD_PRELOAD, loading an attacker-supplied .so into the privileged process. Container escape with root code execution on the host — full node compromise on shared GPU clusters (CVSS 9.0, Critical). You are likely affected if you run NVIDIA Container Toolkit ≤ 1.17.7 and NVIDIA GPU Operator ≤ 25.3.0 (Linux, CDI mode). at the versions noted in the record below. We can audit your cluster against this and the wider class of AI-infrastructure risks and tell you precisely where you are exposed.

Fix: Upgrade NVIDIA Container Toolkit to 1.17.8 or later and NVIDIA GPU Operator to 25.3.1 or later. Mitigation if you cannot patch immediately: If you cannot patch immediately, prevent running untrusted images on GPU nodes, detect containers setting LD_PRELOAD to unusual .so paths (e.g. /proc/self/cwd/*.so), and isolate untrusted workloads with gVisor/Kata. We help you apply the fix safely in production — staged rollout, verification, and the admission/network guardrails that reduce blast radius for the next issue of this class.

Two critical escapes in one component in a year means defence-in-depth, not just patching: least-privilege on GPU nodes, image provenance, and runtime isolation for anything untrusted. This is why we treat the AI-infrastructure supply chain, container runtime, and admission path as security-critical — not just the application layer.

Yes. We run a focused review of your container runtime (NVIDIA Container Toolkit / GPU Operator versions), ingress and admission webhooks, model and image supply chain, agent/tool sandboxing, and RBAC/network policy — mapping each finding to a concrete fix and a guardrail. See our Kubernetes AI security hub.

Both. This page documents a real, publicly disclosed incident with its official source so you can act on it. If you would rather an engineer work it with you — patching safely in production, or auditing for the wider class of risk — that service is available same-day and confidentially.

Official Source

Wiz Research disclosure of NVIDIAScape (CVE-2025-23266) and NVIDIA’s security advisory. Verify affected and fixed versions against the vendor advisory before patching.

Read the Wiz Research disclosure (NVIDIAScape, CVE-2025-23266)

Get Started Today

Exposed to NVIDIAScape (CVE-2025-23266) or Want a Cluster Security Review?

In-house Kubernetes, GPU, and AI-infrastructure security engineers available same-day — safe production patching, blast-radius review, and hardening against this class of risk. Talk to ProxyTechSupport on WhatsApp now.

Proxy Tech Support provides interview preparation, technical guidance, and job support services. All services are advisory and educational in nature.