Database/Control plane, storage & DevOps

IBM Spectrum Scale Local Read Only Cache (LROC): With LROC enabled, a read of one file can silently return the contents
Impact
With LROC enabled, a read of one file can silently return the contents of a different file. A tenant reading its own dataset gets back bytes belonging to someone else, and a training job can ingest another tenant's data without anyone noticing.
Who can reach it
Any user able to read files on a node with LROC enabled. This is a correctness bug in the cache rather than an exploit chain, so it fires during ordinary I/O.
What to do
Upgrade to the fixed Spectrum Scale level. If an upgrade cannot happen right away, disable LROC on affected nodes - the performance loss is far cheaper than cross-tenant data bleed, and any data read while LROC was active should be treated as suspect.
References
Related entries
- DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issue: TurnsCVE-2019-0174 · DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issueLow
- IBM Spectrum Scale file audit logging: A local user touches files without the access being recorded, so the audit trailCVE-2021-29671 · IBM Spectrum Scale file audit loggingLow
- Redis: Crafted Lua script triggers a NULL pointer dereferenceCVE-2022-24736 · RedisLow
- GitLab EE: pending members receive custom-role permissions before their membership is activeCVE-2025-9486 · GitLab EE (custom role assignment, pending membership state)Low
- Grafana: legacy correlation records can be read and permanently deleted across organizationsCVE-2026-21727 · Grafana (Correlations feature, legacy org_id = 0 records)Low
- RabbitMQ: Unsanitized username rendered in the management UICVE-2021-32718 · RabbitMQLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.