Database/Kernel, userspace & hypervisor

IBM Spectrum Scale kernel module: An unauthenticated local trigger takes down the Spectrum Scale kernel module and with
CVSS 7.1CVE-2020-4411Kernel, userspace & hypervisorcurated
Impact
An unauthenticated local trigger takes down the Spectrum Scale kernel module and with it filesystem access on the node. Scope is changed, so the blast radius is the whole node rather than the calling process.
Who can reach it
Local access to a node running Spectrum Scale 4.2.0.0-4.2.3.21 or 5.0.0.0-5.0.4.3. No credentials needed.
What to do
Upgrade to the fixed level named in IBM's bulletin, rebuild the portability layer and reboot each node as it is drained.
References
Related entries
- Xen - x86 IOMMU command timeout detection and handling: Xen's IOMMU command timeout handling is inappropriate, so IOMMUCVE-2021-28692 · Xen - x86 IOMMU command timeout detection and handlingHigh
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): An out-of-bounds access in the amdkfd (KFD computeCVE-2021-4460 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)High
- Xen (x86): Unintended memory sharing between guests - cross-tenant data exposureCVE-2022-42327 · Xen (x86)High
- Linux kernel (arch/x86/kvm): A guest that is not advertised long mode makes the host's SMM emulator walk 16CVE-2022-49883 · Linux kernel (arch/x86/kvm)High
- Linux kernel (drivers/vfio/pci/hisilicon): The VFIO migration save and resume paths do not advance the data pointer byCVE-2023-52453 · Linux kernel (drivers/vfio/pci/hisilicon)High
- Linux kernel (drivers/gpu/drm/vmwgfx): A tenant that asks for a fence event on its DRM fd and then reads the fd backCVE-2024-36960 · Linux kernel (drivers/gpu/drm/vmwgfx)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.