Database/Control plane, storage & DevOps

IBM GPFS command line utility: Any unprivileged user with a shell on a GPFS node can force GPFS down on that node
CVSS 5.5CVE-2018-1783Control plane, storage & DevOpscurated
Impact
Any unprivileged user with a shell on a GPFS node can force GPFS down on that node, cutting every job on it off from the filesystem. On a training cluster that means in-flight runs lose their checkpoint target and die.
Who can reach it
Local account on a GPFS node. No admin rights required - the command line utility itself is the lever.
What to do
Upgrade to the fixed Spectrum Scale level. As a compensating control, restrict execution of the GPFS admin utilities to an admin group rather than leaving them generally executable on shared nodes.
References
Related entries
- Slurm (slurmdbd.conf file permissions): slurmdbd.conf is installed world-readable, which leaks the accountingCVE-2019-19727 · Slurm (slurmdbd.conf file permissions)Medium
- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (improper input validation) reachableCVE-2020-24502 · Intel E810 adapter driver for Linux (< 1.0.4)Medium
- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (insufficient access control leadingCVE-2020-24503 · Intel E810 adapter driver for Linux (< 1.0.4)Medium
- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (uncontrolled resource consumption)CVE-2020-24504 · Intel E810 adapter driver for Linux (< 1.0.4)Medium
- IBM Spectrum Scale mmfsd daemon (RPC request handling): A local attacker floods mmfsd with RPC requests and crashes itCVE-2020-4491 · IBM Spectrum Scale mmfsd daemon (RPC request handling)Medium
- AMD CPU core logic - core hang triggered from an unprivileged VM: Specific code executed from an unprivileged VM canCVE-2021-26339 · AMD CPU core logic - core hang triggered from an unprivileged VMMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.