CVE-2025-23359
Bottlerocket Schwachstellenanalyse und -minderung

Überblick

NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability (CVE-2025-23359) discovered in February 2025. The vulnerability affects all versions of NVIDIA Container Toolkit up to and including 1.17.3 and NVIDIA GPU Operator up to and including 24.9.1. When used with default configuration, this vulnerability allows a crafted container image to gain access to the host file system (NVIDIA Advisory, NVD).

Technische Details

The vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition that enables attackers to mount the host's root filesystem into a container, granting unrestricted access to all host files. The issue received a CVSS v3.1 base score of 8.3 (High) with the vector string AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H. The vulnerability is particularly concerning as it can be exploited through the manipulation of symbolic links and filesystem operations during container initialization (Wiz Blog, Hacker News).

Aufprall

A successful exploitation of this vulnerability can lead to multiple severe consequences including code execution, denial of service, escalation of privileges, information disclosure, and data tampering. While the initial access to the host filesystem is read-only, attackers can leverage access to Unix sockets to launch privileged containers and achieve full host compromise (NVIDIA Advisory, Wiz Blog).

Ausnutzbarkeit

The vulnerability has been confirmed to be exploitable in both standard container environments and those using Google's gVisor security sandbox. The exploit involves manipulating filesystem layouts between mount operations and using symbolic links to trick the container toolkit into mounting host filesystem directories. The attack can be executed through a specially crafted container image (Wiz Blog, Hacker News).

Risikominderung und Problemumgehungen

NVIDIA has released version 1.17.4 of the Container Toolkit and version 24.9.2 of the GPU Operator to address this vulnerability. The fix changes the default behavior of the NVIDIA Container Toolkit, preventing CUDA compatibility libraries from being mounted to the default library path in the container. Users are strongly advised not to disable the --no-cntlibs flag in production environments. For cases requiring CUDA Forward Compatibility, users can set the LD_LIBRARY_PATH environment variable to include /usr/local/cuda/compat, though this may cause portability issues (NVIDIA Advisory).

Reaktionen der Community

The vulnerability was independently discovered and reported by multiple security researchers, including teams from Wiz Research and Trend Micro Research. NVIDIA has acknowledged the researchers' contributions and worked closely with them to ensure proper mitigation of both the original vulnerability and its bypass (NVIDIA Advisory, Wiz Blog).

Zusätzliche Ressourcen


QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt Bottlerocket Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

BRSA-wwrng3fsbmtpHIGHN/A
  • Bottlerocket logoBottlerocket
  • bottlerocket-kernel-6.1
NeinJaJul 27, 2026
BRSA-tncezcgyjaphHIGHN/A
  • Bottlerocket logoBottlerocket
  • kernel-6.18
NeinJaJul 27, 2026
BRSA-2ejbaxkaflesHIGHN/A
  • Bottlerocket logoBottlerocket
  • bottlerocket-kernel-6.12
NeinJaJul 27, 2026
BRSA-zosf9tq7lefrLOWN/A
  • Bottlerocket logoBottlerocket
  • bottlerocket-containerd-2.1
NeinJaJul 24, 2026
BRSA-4xkkdto38tkrLOWN/A
  • Bottlerocket logoBottlerocket
  • bottlerocket-ecr-credential-provider-1.30
NeinJaJul 24, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement