Root cause
A privileged container-initialization component inherited container-controlled execution context without sufficient separation from host authority.
Demonstrated impact
An untrusted container image could lead to code execution with elevated host permissions. Scope depends on runtime configuration; NVIDIA explicitly excludes systems using crun from this CVE.
Lessons for review
- Keep privileged runtime initialization independent of workload-controlled configuration.
- Use layered tenant isolation and verify vendor-specific runtime applicability before remediation.
Award and evidence
One competition-entry award, not the researchers’ event total. Official rules specify US currency; recipient allocation and actual cash settlement are unverified.
Read the researcher’s explicit CVE-to-Pwn2Own submission timeline and matched its date, product and named researchers to the organizer’s individual-entry award; corroborated CVE and scope with vendor guidance. Official rules establish USD denomination.
- Historical technical publication, outside the preferred twelve-month window.
- One awarded competition entry shared by two named researchers; recipient splits and cash-transfer date are unknown.
- NVIDIA credits an additional finder, without assigning that person this competition award.
- Vendor bulletin was updated after initial disclosure; affected configurations and product-specific fixed releases should be read there.
Recorded timeline
- Published
- 2025-07-17explicit · Primary research article publication; earlier competition results are separately dated.
- Public Disclosure
- 2025-05-17explicit · Public demonstration and result; vendor technical advisory followed later.
- Reported
- 2025-05-17explicit · The researchers explicitly date this CVE’s initial vendor report at Pwn2Own to May 17. ZDI separately lists June 5 as its vendor-notification date; that later coordination event is not substituted for the initial report.
- Awarded
- 2025-05-17explicit · Award announced for the named individual entry.
- Award Announced
- 2025-05-17explicit
Sources and provenance
- NVIDIAScape: NVIDIA Container Toolkit CVE-2025-23266 Nir Ohfeld and Shir Tamari / Wiz Research · reviewed 2026-10-02
- Pwn2Own Berlin 2025 daily results Dustin Childs / Zero Day Initiative · reviewed 2026-10-02
- Pwn2Own Berlin 2025 rules Trend Micro Zero Day Initiative · reviewed 2026-10-02
- NVIDIA Container Toolkit security bulletin, July 2025 NVIDIA PSIRT · reviewed 2026-10-02
- ZDI-25-626 NVIDIA Container Toolkit advisory Zero Day Initiative · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.