Database/Control plane, storage & DevOps
Intel oneAPI DPC++/C++ compiler runtime: An uncontrolled library search path: the component loads a shared library
Impact
An uncontrolled library search path: the component loads a shared library by name from a directory a non-root user can write. Anyone who can drop a file in that directory gets code execution in the context of whoever next runs the tool - which on an AI node is usually a privileged installer, a service account, or root.
Who can reach it
A local authenticated user on a node that has the toolkit installed. On shared build/dev nodes and on container images built from the Intel toolkits, that is a broad set of people.
What to do
Upgrade the affected component and, just as importantly, audit directory permissions on already-provisioned nodes and container images - upgrading the package does not remove a writable directory an earlier install created. Userspace only: no reboot, no BIOS, no microcode. Rebuild base images rather than patching running nodes.
References
Related entries
- Intel oneAPI Collective Communications Library (oneCCL): An uncontrolled library search path: the component loadsCVE-2022-26425 · Intel oneAPI Collective Communications Library (oneCCL)Medium
- AMD Radeon RX Vega M graphics driver installer - signature verification: The driver package launchesCVE-2023-20567 · AMD Radeon RX Vega M graphics driver installer - signature verificationMedium
- Intel oneAPI compiler: An uncontrolled library search path: the component loads a shared library by nameCVE-2024-21857 · Intel oneAPI compilerMedium
- Intel oneAPI Level Zero software: An uncontrolled search path in Level Zero lets an authenticated local user get codeCVE-2024-31073 · Intel oneAPI Level Zero softwareMedium
- Intel oneAPI DPC++/C++ compiler: An uncontrolled library search path: the component loads a shared library by nameCVE-2024-47795 · Intel oneAPI DPC++/C++ compilerMedium
- Intel oneAPI toolkit and component installers: An uncontrolled library search path: the component loads a sharedCVE-2025-20017 · Intel oneAPI toolkit and component installersMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.