Database/AI/ML frameworks & serving
Intel oneCCL Bindings for PyTorch: protection mechanism failure allows local privilege escalation
Impact
oneCCL Bindings for PyTorch is the collective-communication layer multi-GPU and multi-node training jobs use on Intel accelerator fleets - the equivalent slot NCCL occupies on NVIDIA nodes. A failed protection mechanism lets an unprivileged local process escalate to the privileges of a privileged user already running on the node, with high confidentiality, integrity and availability impact to that system. On a shared training node that means reach into other jobs' address space, datasets and credentials. Intel's vector requires a privileged user to be present and passive user interaction, which limits it to nodes where root or a high-privilege service account runs oneCCL workloads alongside untrusted ones.
Who can reach it
Local unprivileged user on a node where a privileged user is also running oneCCL-backed PyTorch workloads. No authentication to a network service is needed; requires passive interaction from the privileged user.
What to do
Upgrade Intel oneCCL Bindings for PyTorch to v2.8.0 or later wherever the package is installed - base images, cluster-wide module trees, and per-user environments - then restart the affected training jobs. No reboot or firmware step; the rollout cost is image rebuild plus draining in-flight long jobs. Intel's advisory INTEL-SA-01464 is the authoritative version list.
References
Related entries
- TorchServe (model/workflow API): Information disclosure of files on the serving hostCVE-2023-48299 · TorchServe (model/workflow API)Medium
- llama.cpp (RPC backend): Arbitrary address read via `rpc_tensor.data`CVE-2024-42478 · llama.cpp (RPC backend)Medium
- HuggingFace transformers: ReDoS in `convert_tf_weight_name_to_pt_weight_name`CVE-2025-5197 · HuggingFace transformersMedium
- mcp-kubernetes-server: chained kubectl commands bypass the read-only --disable-write/--disable-delete guardsCVE-2025-59376 · feiskyer mcp-kubernetes-server (--disable-write / --disable-delete command guards)Medium
- Hugging Face Transformers: ReDoS in the English number normalizer burns CPU on crafted inputCVE-2025-6051 · Hugging Face Transformers (EnglishNormalizer.normalize_numbers)Medium
- BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py): A model repository directory name flows unescapedCVE-2026-15035 · BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.