Executive brief
NVIDIA Container Toolkit and GPU Operator for Linux are tools used to manage and run GPU-accelerated applications in containerized environments like Docker or Kubernetes. A security vulnerability has been identified that could allow an attacker to gain higher-level administrative privileges or execute unauthorized code on the host system. This could lead to full system compromise, unauthorized access to sensitive data, or disruption of containerized services.
Technical details
A time-of-check time-of-use (TOCTOU) race condition (CWE-367) exists in the NVIDIA Container Toolkit and GPU Operator for Linux. The vulnerability occurs when the software checks a condition (such as a file property or state) but that condition changes before the software performs an action based on that check. An attacker with low-privileged network access can exploit this timing window to achieve code execution, escalate privileges to a higher level, or tamper with sensitive data. The vulnerability has a CVSS score of 8.5, reflecting its potential for significant impact including scope change to the host system. Affected versions include Container Toolkit up to 1.19.0 and GPU Operator up to 26.3.1.
Affected products
- NVIDIA Container Toolkit All versions up to and including 1.19.0
- NVIDIA GPU Operator All versions up to and including 26.3.1
Timeline
- 2026-07-01: disclosed: Initial publication of the CVE record.
- 2026-07-01: advisory: NVIDIA security bulletin 5850 released.