Database/Kernel, userspace & hypervisor

IBM GPFS kernel module (mmap path): An unprivileged user panics the kernel on a GPFS node just by mmap-ing a file on
Impact
An unprivileged user panics the kernel on a GPFS node just by mmap-ing a file on the filesystem or running a crafted binary stored there. Every job on that node dies with it, and the node needs a reboot.
Who can reach it
Local account with read access to the GPFS filesystem on a node running Spectrum Scale 5.0.1.0 or 5.0.1.1. Any tenant who can place a file on shared storage can trigger it on any node that opens it.
What to do
Upgrade to 5.0.1.2 or later. Because the fault is in the kernel module, the fix needs the portability layer rebuilt and the node drained and rebooted, not just a daemon bounce.
References
Related entries
- Linux kernel (arch/x86/kvm): The guard against accessing bytes 4-15 of an emulated APIC register was dropped, andCVE-2021-47255 · Linux kernel (arch/x86/kvm)Medium
- Intel CPU (Downfall / GDS): Downfall: Gather Data Sampling leaks AVX gather-instruction data across SMT siblingsCVE-2022-40982 · Intel CPU (Downfall / GDS)Medium
- Linux kernel (net/tls): A BPF sockmap psock could be attached to a socket that already had the kTLS ULP installed. TheCVE-2022-49732 · Linux kernel (net/tls)Medium
- AMD CPU (Zenbleed): Zenbleed: cross-process/cross-VM register-file data leak on Zen 2 at ~30 kB/s per core, no specialCVE-2023-20593 · AMD CPU (Zenbleed)Medium
- GPU local/shared memory not cleared between kernels (AMD, Apple, Qualcomm, Imagination): A GPU kernel reads whateverCVE-2023-4969 · GPU local/shared memory not cleared between kernels (AMD, Apple, Qualcomm, Imagination)Medium
- Linux kernel (net/xfrm): XFRM_MSG_NEWAE lets a caller update replay-window state on a state that never had replay_esnCVE-2023-53147 · Linux kernel (net/xfrm)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.