We use cookies to improve your experience on our site.
AVID-2026-R1005
Description
Vulnerability CVE-2022-26076
Details
Uncontrolled search path element in the Intel(R) oneAPI Deep Neural Network (oneDNN) before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Reason for inclusion in AVID: CVE-2022-26076 describes an uncontrolled search path element vulnerability in Intel oneAPI Deep Neural Network library (oneDNN), a software component commonly used in AI frameworks. As a software dependency in AI stacks, its exploitation could privilege-escalate locally, impacting AI deployments. This is a software supply-chain vulnerability in a component used to build/run AI systems. The report includes CVE reference and vendor advisory, providing sufficient evidence.
References
Affected or Relevant Artifacts
- Developer: n/a
- Deployer: n/a
- Artifact Details:
| Type | Name |
|---|---|
| System | Intel(R) oneAPI Deep Neural Network (oneDNN) |
Impact
AVID Taxonomy Categorization
- Risk domains: Security
- SEP subcategories: S0100: Software Vulnerability
- Lifecycle stages: L06: Deployment
CVSS
| Version | 3.1 |
| Vector String | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Base Score | 6.7 |
| Base Severity | 🟠 Medium |
| Attack Vector | LOCAL |
| Attack Complexity | 🔴 High |
| Privileges Required | 🟢 Low |
| User Interaction | REQUIRED |
| Scope | UNCHANGED |
| Confidentiality Impact | 🔴 High |
| Integrity Impact | 🔴 High |
| Availability Impact | 🔴 High |
Other information
- Report Type: Advisory
- Credits:
- Date Reported: 2023-02-16
- Version: 0.3.3
- AVID Entry