Database/Control plane, storage & DevOps
Intel C++ Compiler Classic / oneAPI toolkits (Unicode source handling): Improper handling of Unicode bidirectional
Impact
Improper handling of Unicode bidirectional and homoglyph characters in source code means the compiler can build something materially different from what a reviewer reads. This is the Trojan Source class - a supply-chain problem for anyone compiling third-party or contributor-supplied kernels and operators into their inference stack.
Who can reach it
Anyone who can get source into your build - an internal contributor, a vendored dependency, or a model-op repo you compile from.
What to do
Upgrade the compiler to 2021.6 / oneAPI 2022.2 or later, and add a CI check that rejects bidirectional control characters in source. Build-toolchain change only - no node reboot, no firmware. Rebuild any artefact compiled with an affected compiler if provenance matters.
References
Related entries
- Intel oneAPI DPC++/C++ compiler (homoglyph rendering): Homoglyph characters are not visually distinguishedCVE-2022-26843 · Intel oneAPI DPC++/C++ compiler (homoglyph rendering)High
- Pure Storage FlashBlade authentication input validation: The FlashBlade equivalent of the FlashArray pre-authenticationCVE-2025-0052 · Pure Storage FlashBlade authentication input validationHigh
- Dell Chassis Management Controller (PowerEdge FX2 / VRTX): Unauthenticated remote attacker overflows a stack bufferCVE-2025-26336 · Dell Chassis Management Controller (PowerEdge FX2 / VRTX)High
- VMware Avi Load Balancer: authorization bypass exposes part of the Avi Controller control planeCVE-2026-47866 · VMware Avi Load Balancer (Avi Controller control plane)High
- Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key): WMCO opens SSH to Windows worker nodesCVE-2026-54100 · Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key)High
- Coder: workspace agent redirects let one tenant read, write and execute in another's workspaceCVE-2026-63443 · Coder (workspace agent API client, agentConn.apiClient redirect handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.