GPU VulnDB

Database/Control plane, storage & DevOps

Intel oneAPI DPC++/C++ compiler installer: The compiler installer sets permissions that let a local user modify

CVE-2025-20087Control plane, storage & DevOpscurated

Impact

The compiler installer sets permissions that let a local user modify installed files that later execute with higher privilege. Same practical outcome as the search-path family: local privilege escalation on shared build and training nodes.

Who can reach it

A local authenticated user on a node that has the toolkit installed. On shared build/dev nodes and on container images built from the Intel toolkits, that is a broad set of people.

What to do

Upgrade the affected component and, just as importantly, audit directory permissions on already-provisioned nodes and container images - upgrading the package does not remove a writable directory an earlier install created. Userspace only: no reboot, no BIOS, no microcode. Rebuild base images rather than patching running nodes.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.