Race Condition Vulnerability in NVIDIA Container Toolkit for Linux
CVE-2026-24260

8.5HIGH

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
1 July 2026

What is CVE-2026-24260?

The NVIDIA Container Toolkit for Linux has a vulnerability that allows an attacker to exploit a time-of-check, time-of-use race condition. This flaw could potentially result in unauthorized code execution, giving an attacker the ability to escalate privileges and tamper with data. Addressing this vulnerability is crucial to protect systems using this toolkit from malicious actions.

Affected Version(s)

Container Toolkit Linux All versions up to and including 1.19.0

GPU Operator Linux All versions up to and including 26.3.1

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.