GPU VulnDB

Database/Kernel, userspace & hypervisor

IBM GPFS kernel module (mmap path): An unprivileged user panics the kernel on a GPFS node just by mmap-ing a file on

CVE-2018-1782Kernel, userspace & hypervisorcurated

Impact

An unprivileged user panics the kernel on a GPFS node just by mmap-ing a file on the filesystem or running a crafted binary stored there. Every job on that node dies with it, and the node needs a reboot.

Who can reach it

Local account with read access to the GPFS filesystem on a node running Spectrum Scale 5.0.1.0 or 5.0.1.1. Any tenant who can place a file on shared storage can trigger it on any node that opens it.

What to do

Upgrade to 5.0.1.2 or later. Because the fault is in the kernel module, the fix needs the portability layer rebuilt and the node drained and rebooted, not just a daemon bounce.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.