Database/Control plane, storage & DevOps

IBM Spectrum LSF (job submission, file permissions): Weak file permissions in the LSF install let a local user change
Impact
Weak file permissions in the LSF install let a local user change the user a job is submitted as. On a shared GPU cluster that means running your workload under someone else's identity, charged to their account and with access to their data.
Who can reach it
A local user on an LSF submission host, affecting LSF 9.1.1, 9.1.2, 9.1.3 and 10.1.
What to do
Apply IBM's LSF fix pack and, separately, tighten the permissions on the LSF configuration and binary directories - the underlying issue is filesystem mode, so the correct modes need to be verified after every LSF upgrade, not just once.
References
Related entries
- AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016): Insufficient RMP checking on IOMMU host bufferCVE-2023-20585 · AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016)Medium
- ZKTeco BioAccess IVS v3.3.1 access control platform: An unauthenticated attacker can open and close any doorCVE-2023-38958 · ZKTeco BioAccess IVS v3.3.1 access control platformMedium
- Intel Data Center GPU Flex Series - Windows driver software: Improper access control in the Flex Series Windows driverCVE-2024-43101 · Intel Data Center GPU Flex Series - Windows driver softwareMedium
- Grafana: Org Admin can read dashboard permission mappings belonging to other organizationsCVE-2026-11817 · Grafana access-control API (/api/access-control/users/permissions/search), multi-org stacksMedium
- OpenChoreo: autobuild webhook picks its provider from a caller-supplied header and accepts unsigned Bitbucket requestsCVE-2026-73840 · OpenChoreo API (POST /api/v1alpha1/autobuild webhook handler)Medium
- GitLab CE/EE: improper authorization on internal endpoints exposes credentials and tokensCVE-2026-82837 · GitLab CE/EE (internal data emission endpoints, authorization)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.