GPU VulnDB

Database/AI/ML frameworks & serving

Intel oneCCL Bindings for PyTorch: protection mechanism failure allows local privilege escalation

CVSS 5.4CVE-2026-24693AI/ML frameworks & servingcurated

Impact

oneCCL Bindings for PyTorch is the collective-communication layer multi-GPU and multi-node training jobs use on Intel accelerator fleets - the equivalent slot NCCL occupies on NVIDIA nodes. A failed protection mechanism lets an unprivileged local process escalate to the privileges of a privileged user already running on the node, with high confidentiality, integrity and availability impact to that system. On a shared training node that means reach into other jobs' address space, datasets and credentials. Intel's vector requires a privileged user to be present and passive user interaction, which limits it to nodes where root or a high-privilege service account runs oneCCL workloads alongside untrusted ones.

Who can reach it

Local unprivileged user on a node where a privileged user is also running oneCCL-backed PyTorch workloads. No authentication to a network service is needed; requires passive interaction from the privileged user.

What to do

Upgrade Intel oneCCL Bindings for PyTorch to v2.8.0 or later wherever the package is installed - base images, cluster-wide module trees, and per-user environments - then restart the affected training jobs. No reboot or firmware step; the rollout cost is image rebuild plus draining in-flight long jobs. Intel's advisory INTEL-SA-01464 is the authoritative version list.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.