Executive brief
Intel's oneCCL Bindings for PyTorch is a distributed computing library for machine learning frameworks. A protection mechanism failure allows local attackers with high privilege to escalate privileges further, potentially compromising system confidentiality, integrity, and availability. Intel has discontinued support for this product and recommends immediate uninstallation.
Technical details
This vulnerability is a protection mechanism failure (Ring 3 escape) in Intel oneCCL Bindings for PyTorch versions before v2.8.0. The issue requires local access combined with high privilege (privileged user) and passive user interaction to trigger, but uses low attack complexity. An attacker with these preconditions can escalate privileges and potentially compromise the confidentiality, integrity, and availability of the affected system. Intel has not released patches and instead issued a Product Discontinuation Notice, recommending users uninstall or cease using the software immediately.
Affected products
- Intel oneCCL Bindings for PyTorch before v2.8.0
Timeline
- 2026-08-11: disclosed