Vulnerability is in the NVIDIA kernel-mode driver (nvidia.ko / open kernel module). Echo ships only the userspace
cuda-compat libraries (libcuda, nvvm, ptxjitcompiler, ...) via the cuda-* packages; that
component is provided by the host, not the image.
https://github.com/NVIDIA/product-security/tree/main/2026/5861