GPU VulnDB

Database/AI/ML frameworks & serving

Intel Extension for PyTorch: unsafe deserialization of untrusted data allows local privilege escalation

CVSS 4.6CVE-2026-35502AI/ML frameworks & servingcurated

Impact

Intel Extension for PyTorch is the IPEX layer that training and inference jobs load on Intel GPU and CPU nodes. Loading a crafted serialized artifact lets an unprivileged local user gain the privileges of whichever account ran the job, which on a shared accelerator node is often a long-lived service or notebook user with access to other tenants' checkpoints and dataset mounts. Intel rates confidentiality, integrity and availability impact as low and the vector requires active user interaction, so this is a job-level compromise rather than a node takeover. The practical exposure is model-file and checkpoint provenance: anything that hands IPEX a file from an untrusted tenant is the attack path.

Who can reach it

Local, unauthenticated user on a node running Intel Extension for PyTorch, who can place or supply a serialized artifact that a privileged-enough user then loads. Requires active user interaction - something must open the attacker-supplied data.

What to do

Upgrade Intel Extension for PyTorch to 2.8.0 or later in the images and conda/pip environments your training and inference jobs use, then restart the affected jobs or serving daemons. No node reboot or firmware work is needed; the cost is rebuilding and rolling container images across the fleet. Until then, treat model files and checkpoints from other tenants as untrusted input.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.