Altair Grid Engine (shared library loading): Grid Engine does not sanitise the environment variables that control
Impact
Grid Engine does not sanitise the environment variables that control shared-library search, so a local user gets their own code loaded into a privileged Grid Engine process. That is a straight local privilege escalation on scheduler and execution hosts.
Who can reach it
A local user on a Grid Engine host who can set the environment of a Grid Engine binary - which includes anyone submitting jobs through the local commands. All versions before V2026.0.0.
What to do
Upgrade Altair Grid Engine to V2026.0.0. This ships in the same Siemens advisory as CVE-2025-40760, so treat them as one upgrade.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.