Database/Control plane, storage & DevOps

IBM Spectrum Scale core component (format string handling): A user with a shell on any node that runs Storage Scale
Impact
A user with a shell on any node that runs Storage Scale gets arbitrary code execution inside the core storage process, which runs privileged. From there the whole node's view of the filesystem is under attacker control.
Who can reach it
Local, low-privileged account on a node running the Storage Scale core component - in practice any compute node with the client mounted, including a tenant's own job container if it can reach the host.
What to do
Apply the Storage Scale efix listed in IBM's bulletin for the 5.0.x / 5.1.0.x line and restart the daemon on each node in a rolling fashion. Audit which non-admin accounts have local shells on nodes that run the core component.
References
Related entries
- Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191: Use-after-freeCVE-2022-29919 · Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191High
- Ceph: ceph-crash.service local privilege escalation to root plus privileged crash-dump disclosureCVE-2022-3650 · CephHigh
- Ampere Altra before 1.08g and Altra Max before 2.05a - return address prediction: An attacker can controlCVE-2022-37459 · Ampere Altra before 1.08g and Altra Max before 2.05a - return address predictionHigh
- IBM Storage Scale Container Native Storage Access (pod security context): A local user in a CNSA-served containerCVE-2022-43831 · IBM Storage Scale Container Native Storage Access (pod security context)High
- IBM Spectrum Scale container image (command execution): A local attacker runs arbitrary commands inside the SpectrumCVE-2022-43867 · IBM Spectrum Scale container image (command execution)High
- AMD SMM - memory corruption (AMD-SB-4003): Memory corruption reachable in System Management Mode. Same class as theCVE-2023-20555 · AMD SMM - memory corruption (AMD-SB-4003)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.