Organizations utilizing managed AI services from major cloud providers face immediate exposure, as a single malicious container could compromise entire host systems and access sensitive data belonging to multiple tenants. The vulnerability affects all NVIDIA Container Toolkit versions up to v1.17.7 and poses systemic risks to multi-tenant AI cloud environments where customers deploy custom container images on shared GPU infrastructure. The vulnerability allows malicious actors to break free from container isolation and achieve complete root-level control over host systems running GPU-accelerated workloads. The toolkit, which serves as the critical bridge between containerized AI applications and NVIDIA GPUs, inadvertently inherits environment variables from container images during the createContainer hook execution phase. The malicious payload leverages the Linux LD_PRELOAD environment variable to inject code into privileged processes during container initialization, transforming what should be isolated workloads into system-compromising threats. A critical container escape vulnerability has emerged in the NVIDIA Container Toolkit, threatening the security foundation of AI infrastructure worldwide. When a malicious container image contains the environment variable LD_PRELOAD=/proc/self/cwd/poc.so, the toolkit’s privileged hook process loads and executes the attacker’s shared library file directly from the container filesystem. Wiz.io analysts identified that the vulnerability stems from a fundamental flaw in how the NVIDIA Container Toolkit handles Open Container Initiative (OCI) hooks. Researchers have demonstrated that a mere three-line Dockerfile can weaponize this vulnerability, enabling attackers to bypass all container security boundaries. This deceptively simple payload grants immediate root access to the underlying host system, bypassing all container isolation mechanisms. The attack vector exploits the container runtime’s trust relationship with the NVIDIA Container Toolkit. This creates an attack surface where malicious environment variables can influence privileged host processes, leading to complete system compromise. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis.
This Cyber News was published on cybersecuritynews.com. Publication date: Mon, 21 Jul 2025 05:55:14 +0000