Altair Grid Engine (shared library loading): Grid Engine does not sanitise the environment variables that control
Impact
Grid Engine does not sanitise the environment variables that control shared-library search, so a local user gets their own code loaded into a privileged Grid Engine process. That is a straight local privilege escalation on scheduler and execution hosts.
Who can reach it
A local user on a Grid Engine host who can set the environment of a Grid Engine binary - which includes anyone submitting jobs through the local commands. All versions before V2026.0.0.
What to do
Upgrade Altair Grid Engine to V2026.0.0. This ships in the same Siemens advisory as CVE-2025-40760, so treat them as one upgrade.
References
Related entries
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): Missing or insufficient validation of user-suppliedCVE-2025-68286 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux kernel amdgpu RAS / GPU reset and recovery path (drm/amdgpu): A use-after-free in the amdgpu RAS / GPU reset andCVE-2025-68793 · Linux kernel amdgpu RAS / GPU reset and recovery path (drm/amdgpu)High
- NVIDIA Model Optimizer: RCE via unsafe deserializationCVE-2026-24141 · NVIDIA Model OptimizerHigh
- NVIDIA Megatron-LM: A further script-level code-injection path, filed under the same class as the 2025 setCVE-2026-24149 · NVIDIA Megatron-LMHigh
- NVIDIA Megatron-LM: Checkpoint loading reaches remote code execution when a user loads a crafted checkpointCVE-2026-24150 · NVIDIA Megatron-LMHigh
- NVIDIA Megatron-LM: The inferencing path reaches remote code execution on crafted inputCVE-2026-24151 · NVIDIA Megatron-LMHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.