Database/Control plane, storage & DevOps
Intel oneAPI DPC++/C++ compiler (homoglyph rendering): Homoglyph characters are not visually distinguished
CVSS 8.3CVE-2022-26843Control plane, storage & DevOpscurated
Impact
Homoglyph characters are not visually distinguished by the toolchain, so two different identifiers can look identical in review. Companion to the bidirectional-override issue and part of the same supply-chain risk when compiling contributed GPU kernels.
Who can reach it
Anyone whose source reaches your compiler.
What to do
Upgrade to oneAPI 2022.1 or later and screen source for confusable identifiers in CI. Toolchain-only, no reboot.
References
Related entries
- Pure Storage FlashBlade authentication input validation: The FlashBlade equivalent of the FlashArray pre-authenticationCVE-2025-0052 · Pure Storage FlashBlade authentication input validationHigh
- Dell Chassis Management Controller (PowerEdge FX2 / VRTX): Unauthenticated remote attacker overflows a stack bufferCVE-2025-26336 · Dell Chassis Management Controller (PowerEdge FX2 / VRTX)High
- VMware Avi Load Balancer: authorization bypass exposes part of the Avi Controller control planeCVE-2026-47866 · VMware Avi Load Balancer (Avi Controller control plane)High
- Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key): WMCO opens SSH to Windows worker nodesCVE-2026-54100 · Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key)High
- Coder: workspace agent redirects let one tenant read, write and execute in another's workspaceCVE-2026-63443 · Coder (workspace agent API client, agentConn.apiClient redirect handling)High
- Renovate: mutual-TLS private key written to logs in cleartext when it appears outside its own fieldCVE-2026-88883 · Renovate self-hosted (log redaction of hostRules[].httpsPrivateKey)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.