CVE-2014-0748: Cray Linux Environment
High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.
apinit on Cray devices with CLE before 4.2.UP02 and 5.x before 5.1.UP00 does not use alpsauth data to validate the UID in a launch message, which allows local users to gain privileges via a modified aprun program, aka ID FN5912.
Affected products
- Cray Cray Linux Environment: up to and including 4.2; version 5.1 only
Published 2014-12-27. Last modified 2026-06-17.