Database/Kernel, userspace & hypervisor
Intel oneAPI Math Kernel Library (oneMKL): An uncontrolled library search path: the component loads a shared library
Impact
An uncontrolled library search path: the component loads a shared library by name from a directory a non-root user can write. Anyone who can drop a file in that directory gets code execution in the context of whoever next runs the tool - which on an AI node is usually a privileged installer, a service account, or root.
Who can reach it
A local authenticated user on a node that has the toolkit installed. On shared build/dev nodes and on container images built from the Intel toolkits, that is a broad set of people.
What to do
Upgrade the affected component and, just as importantly, audit directory permissions on already-provisioned nodes and container images - upgrading the package does not remove a writable directory an earlier install created. Userspace only: no reboot, no BIOS, no microcode. Rebuild base images rather than patching running nodes.
References
Related entries
- Linux kernel - NVMe-oF target configfs, drivers/nvme/target/configfs.c: Nvmet_root_discovery_nqn_store() treated theCVE-2024-53681 · Linux kernel - NVMe-oF target configfs, drivers/nvme/target/configfs.cMedium
- polkit: out-of-bounds write parsing deeply nested XML policy filesCVE-2025-7519 · polkit (XML policy parser, nested-element depth)Medium
- systemd-homed: local homed-managed user can gain membership in arbitrary system groupsCVE-2026-16742 · systemd-homed (homed-managed user record group membership)Medium
- systemd-machined: unvalidated RegisterMachine class lets a local user reach root command executionCVE-2026-4105 · systemd-machined (RegisterMachine D-Bus method, class parameter validation)Medium
- QEMU virtio-blk: malformed guest SCSI request causes host-heap out-of-bounds writeCVE-2026-48914 · QEMU virtio-blk device (SCSI request descriptor size validation)Medium
- Linux kernel (AF_UNIX): Use-after-free in unix_stream_sendpage - local privilege escalation, no capabilities neededCVE-2023-4622 · Linux kernel (AF_UNIX)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.