GPU VulnDB

Database/Kernel, userspace & hypervisor

IBM Spectrum Scale kernel module: An unauthenticated local trigger takes down the Spectrum Scale kernel module and with

CVE-2020-4411Kernel, userspace & hypervisorcurated

Impact

An unauthenticated local trigger takes down the Spectrum Scale kernel module and with it filesystem access on the node. Scope is changed, so the blast radius is the whole node rather than the calling process.

Who can reach it

Local access to a node running Spectrum Scale 4.2.0.0-4.2.3.21 or 5.0.0.0-5.0.4.3. No credentials needed.

What to do

Upgrade to the fixed level named in IBM's bulletin, rebuild the portability layer and reboot each node as it is drained.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.