Database/Control plane, storage & DevOps

IBM GPFS command line utility: Any unprivileged user with a shell on a GPFS node can force GPFS down on that node
CVE-2018-1783Control plane, storage & DevOpscurated
Impact
Any unprivileged user with a shell on a GPFS node can force GPFS down on that node, cutting every job on it off from the filesystem. On a training cluster that means in-flight runs lose their checkpoint target and die.
Who can reach it
Local account on a GPFS node. No admin rights required - the command line utility itself is the lever.
What to do
Upgrade to the fixed Spectrum Scale level. As a compensating control, restrict execution of the GPFS admin utilities to an admin group rather than leaving them generally executable on shared nodes.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.