vulns.co
/
GKData.io MCP

CLCloud permissions and isolation · 2 min read

NVIDIA container initialization inherited untrusted execution context

ZDI awarded Wiz researchers USD 30,000 for this single Pwn2Own Berlin 2025 entry.

Read the primary source CLCloud permissions and isolationReviewed 2026-10-02

Root cause

A privileged container-initialization component inherited container-controlled execution context without sufficient separation from host authority.

Demonstrated impact

An untrusted container image could lead to code execution with elevated host permissions. Scope depends on runtime configuration; NVIDIA explicitly excludes systems using crun from this CVE.

Lessons for review

  • Keep privileged runtime initialization independent of workload-controlled configuration.
  • Use layered tenant isolation and verify vendor-specific runtime applicability before remediation.

Award and evidence

USD 30,000Competition Award · Organizer Confirmed

One competition-entry award, not the researchers’ event total. Official rules specify US currency; recipient allocation and actual cash settlement are unverified.

Read the researcher’s explicit CVE-to-Pwn2Own submission timeline and matched its date, product and named researchers to the organizer’s individual-entry award; corroborated CVE and scope with vendor guidance. Official rules establish USD denomination.

  • Historical technical publication, outside the preferred twelve-month window.
  • One awarded competition entry shared by two named researchers; recipient splits and cash-transfer date are unknown.
  • NVIDIA credits an additional finder, without assigning that person this competition award.
  • Vendor bulletin was updated after initial disclosure; affected configurations and product-specific fixed releases should be read there.

Recorded timeline

Published
2025-07-17explicit · Primary research article publication; earlier competition results are separately dated.
Public Disclosure
2025-05-17explicit · Public demonstration and result; vendor technical advisory followed later.
Reported
2025-05-17explicit · The researchers explicitly date this CVE’s initial vendor report at Pwn2Own to May 17. ZDI separately lists June 5 as its vendor-notification date; that later coordination event is not substituted for the initial report.
Awarded
2025-05-17explicit · Award announced for the named individual entry.
Award Announced
2025-05-17explicit

Sources and provenance

  1. NVIDIAScape: NVIDIA Container Toolkit CVE-2025-23266 Nir Ohfeld and Shir Tamari / Wiz Research · reviewed 2026-10-02
  2. Pwn2Own Berlin 2025 daily results Dustin Childs / Zero Day Initiative · reviewed 2026-10-02
  3. Pwn2Own Berlin 2025 rules Trend Micro Zero Day Initiative · reviewed 2026-10-02
  4. NVIDIA Container Toolkit security bulletin, July 2025 NVIDIA PSIRT · reviewed 2026-10-02
  5. ZDI-25-626 NVIDIA Container Toolkit advisory Zero Day Initiative · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software