Database/Control plane, storage & DevOps

IBM Spectrum Scale daemon (GSKit cryptographic library dependency): A local attacker takes control of the Spectrum
Impact
A local attacker takes control of the Spectrum Scale daemon and from there reads and modifies any file in the shared filesystem, regardless of which tenant owns it. Training data, checkpoints and model artifacts are all in scope.
Who can reach it
Local account on a node running Spectrum Scale 4.1.1 through 5.0.0. The flaw is in the bundled GSKit crypto library that the daemon links, so it is reachable from ordinary node access rather than through a network service.
What to do
Apply the Spectrum Scale efix that ships the fixed GSKit level. This one is worth treating as urgent rather than as routine third-party library hygiene, because the outcome is control of the daemon that enforces file ownership.
References
Related entries
- Arista CloudVision Portal (Configlet Builder API): A read-only CloudVision user escapes their permissions throughCVE-2019-18181 · Arista CloudVision Portal (Configlet Builder API)High
- MUNGE (SUSE/openSUSE packaging): The munge package's install scripts follow symlinks, so a local attacker who controlsCVE-2019-3691 · MUNGE (SUSE/openSUSE packaging)High
- IBM Spectrum Scale administrative command path: A local unprivileged user becomes root on a Storage Scale node byCVE-2019-4558 · IBM Spectrum Scale administrative command pathHigh
- targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)CVE-2020-10699 · targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)High
- IBM Platform LSF / Spectrum LSF Suite (debug configuration file permissions): With specific debug settings enabled, LSFCVE-2020-4278 · IBM Platform LSF / Spectrum LSF Suite (debug configuration file permissions)High
- IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials): A user who is merely allowed to submit LSF jobsCVE-2020-4983 · IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.