Database/Control plane, storage & DevOps
AMD Optimizing CPU Libraries (AOCL) - installation directory permissions: AOCL installs with permissive directory
Impact
AOCL installs with permissive directory permissions, so a low-privileged user can replace library files that privileged processes later load - straightforward privilege escalation to arbitrary code execution. Worth flagging for AI operators specifically: AOCL (BLIS, libFLAME, AOCL-LibM) is exactly what gets installed on AMD nodes to accelerate the CPU side of an ML pipeline, so it is likely present on your hosts and likely loaded by jobs running as someone else.
Who can reach it
Local, low-privileged user who can write into the AOCL installation directory. If tenants share a node and AOCL lives somewhere world-writable, one tenant poisons the next tenant's math library.
What to do
Update AOCL and correct the directory permissions - this is a filesystem ACL fix plus a package update, no reboot and no firmware. Audit the permissions on every math and ML library directory on shared nodes while you are there; the same mistake recurs across vendor-supplied HPC packages.
References
Related entries
- Intel Data Center GPU Flex Series - Windows driver: Improper buffer restrictions in the Flex Series Windows driver letCVE-2024-36292 · Intel Data Center GPU Flex Series - Windows driverHigh
- AMD Optimizing CPU Libraries (AOCL) - DLL hijacking: A DLL search-order hijack in AOCL lets an attacker getCVE-2024-36339 · AMD Optimizing CPU Libraries (AOCL) - DLL hijackingHigh
- Dell OpenManage Server Administrator (XSL hijacking local privilege escalation): A local low-privileged user hijacksCVE-2024-37130 · Dell OpenManage Server Administrator (XSL hijacking local privilege escalation)High
- Intel Data Center GPU Flex Series - Windows driver: A further improper access control in the Flex Series Windows driverCVE-2024-45333 · Intel Data Center GPU Flex Series - Windows driverHigh
- Nx @nx/docker: config-controlled shell injection in release commands executes code in the release jobCVE-2026-104859 · Nx @nx/docker release pipeline (repositoryName / registryUrl shell interpolation)High
- ansible.posix authorized_key: a symlink under a user's ~/.ssh redirects a root chown to any pathCVE-2026-11837 · ansible.posix collection - authorized_key module (keyfile() ownership handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.