GPU VulnDB

Database/Control plane, storage & DevOps

IBM Platform LSF / Spectrum LSF Suite (debug configuration file permissions): With specific debug settings enabled, LSF

CVE-2020-4278Control plane, storage & DevOpsIBM X-Force 176137curated

Impact

With specific debug settings enabled, LSF writes files with permissions loose enough for a local user to escalate to the privileges of the LSF daemons. On the master host that is effectively control of the scheduler, so it is a route from one tenant's shell to deciding what runs where.

Who can reach it

A local user on an LSF host where the debug configuration is active. Affects Platform LSF 9.1 and 10.1, Spectrum LSF Suite 10.2 and Spectrum Suite for HPA 10.2.

What to do

Apply IBM's fix, and turn off the LSF debug settings in production - they are a troubleshooting aid, and leaving them on permanently is what makes this exploitable at all.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.