Database/Control plane, storage & DevOps
Intel oneAPI DPC++/C++ compiler installer: The compiler installer sets permissions that let a local user modify
Impact
The compiler installer sets permissions that let a local user modify installed files that later execute with higher privilege. Same practical outcome as the search-path family: local privilege escalation on shared build and training nodes.
Who can reach it
A local authenticated user on a node that has the toolkit installed. On shared build/dev nodes and on container images built from the Intel toolkits, that is a broad set of people.
What to do
Upgrade the affected component and, just as importantly, audit directory permissions on already-provisioned nodes and container images - upgrading the package does not remove a writable directory an earlier install created. Userspace only: no reboot, no BIOS, no microcode. Rebuild base images rather than patching running nodes.
References
Related entries
- Intel oneAPI DPC++/C++ compiler: An uncontrolled library search path: the component loads a shared library by nameCVE-2025-20627 · Intel oneAPI DPC++/C++ compilerMedium
- Intel E810 NVM Update Utility: Insecure inherited permissions in the NVM update utilityCVE-2025-20629 · Intel E810 NVM Update UtilityMedium
- Dell CloudLink (privilege escalation to database): A privileged user escalates laterally or reads the CloudLinkCVE-2025-46366 · Dell CloudLink (privilege escalation to database)Medium
- Dell CloudLink (risky cryptographic primitive): Use of a cryptographic primitive with a risky implementationCVE-2025-46424 · Dell CloudLink (risky cryptographic primitive)Medium
- JumpServer: Jinja2 injection in Applet Host fields executes commands on the control nodeCVE-2026-44845 · JumpServer (Applet Host deployment, Jinja2 template injection)Medium
- GlusterFS (glusterd management): An authenticated TLS client can use gluster cli --remote-host to add itself to theCVE-2018-10841 · GlusterFS (glusterd management)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.