Database/AI/ML frameworks & serving
Intel Extension for PyTorch: unsafe deserialization of untrusted data allows local privilege escalation
Impact
Intel Extension for PyTorch is the IPEX layer that training and inference jobs load on Intel GPU and CPU nodes. Loading a crafted serialized artifact lets an unprivileged local user gain the privileges of whichever account ran the job, which on a shared accelerator node is often a long-lived service or notebook user with access to other tenants' checkpoints and dataset mounts. Intel rates confidentiality, integrity and availability impact as low and the vector requires active user interaction, so this is a job-level compromise rather than a node takeover. The practical exposure is model-file and checkpoint provenance: anything that hands IPEX a file from an untrusted tenant is the attack path.
Who can reach it
Local, unauthenticated user on a node running Intel Extension for PyTorch, who can place or supply a serialized artifact that a privileged-enough user then loads. Requires active user interaction - something must open the attacker-supplied data.
What to do
Upgrade Intel Extension for PyTorch to 2.8.0 or later in the images and conda/pip environments your training and inference jobs use, then restart the affected jobs or serving daemons. No node reboot or firmware work is needed; the cost is rebuilding and rolling container images across the fleet. Until then, treat model files and checkpoints from other tenants as untrusted input.
References
Related entries
- diffusers (shard file loader): Path traversal in `_get_checkpoint_shard_files`CVE-2026-65920 · diffusers (shard file loader)Medium
- vLLM: derender endpoints process caller-supplied response objects before limits, exhausting CPU and memoryCVE-2026-71486 · vLLM OpenAI-compatible server (/v1/completions/derender and /v1/chat/completions/derender)Medium
- AMD graphics driver - dynamic power management (DPM) array index validation: An unvalidated array index in the driver'sCVE-2023-31306 · AMD graphics driver - dynamic power management (DPM) array index validationLow
- wandb SDK (`ArtifactManifestEntry.download`): Hash-handling weakness in artifact download integrityCVE-2026-15605 · wandb SDK (`ArtifactManifestEntry.download`)Low
- vLLM (prefix cache hash collisions): Crafted prompts collide hashesCVE-2025-25183 · vLLM (prefix cache hash collisions)Low
- vLLM (prefix cache): Prefix-cache timing side channel leaks other tenants' promptsCVE-2025-46570 · vLLM (prefix cache)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.