Database/Control plane, storage & DevOps

Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05
Impact
Unprivileged readers get fine-grained CPU power telemetry, which is a data-dependent side channel: power correlates with the operands being processed, so it leaks key material and other secrets from workloads sharing the socket. On a multi-tenant Arm node this is a cross-tenant leak that needs no memory access at all - just a file read in sysfs. It is also a nuisance for anyone selling confidential inference, because the power trace of a model serving run is itself informative about the workload.
Who can reach it
Any unprivileged local user or container on an Altra / Altra Max host with the HWmon power sensors exposed. Containers that inherit the host sysfs make this trivially available to tenants.
What to do
Update to Altra SRP 1.08b / Altra Max SRP 2.05 or later, which restricts the telemetry. Flash + reboot + drain. Cheaper interim control that works today: restrict access to the HWmon power sensors (root-only permissions, do not bind-mount host /sys into tenant containers, drop the sensor nodes from the container's device allowlist). Losing per-core power telemetry costs you some capacity-planning visibility - decide whether your scheduler actually consumes it before turning it off fleet-wide.
References
Related entries
- Carel pCOWeb HVAC BACnet gateway 2.1.0 (logdownload.cgi): Unauthenticated arbitrary file read off the gatewayCVE-2022-37122 · Carel pCOWeb HVAC BACnet gateway 2.1.0 (logdownload.cgi)High
- FlyteAdmin (built-in OAuth authorization server, default client secret hashes): Turning on Flyte's built-inCVE-2022-39273 · FlyteAdmin (built-in OAuth authorization server, default client secret hashes)High
- IBM Storage Scale Container Native Storage Access (network namespace exposure): Hosts outside the cluster can openCVE-2022-41738 · IBM Storage Scale Container Native Storage Access (network namespace exposure)High
- Schneider Electric APC NetBotz 4 environmental appliances (355/450/455/550/570, V4.7.0 and prior): No rate limitingCVE-2022-43377 · Schneider Electric APC NetBotz 4 environmental appliances (355/450/455/550/570, V4.7.0 and prior)High
- Linux nfsd (NFS server): NFSD buffer overflow - a client can force the send buffer to overflow the page arrayCVE-2022-43945 · Linux nfsd (NFS server)High
- GlusterFS (dht translator, dht_setxattr_mds_cbk): A use-after-free in the distributed-hash translator crashes the brickCVE-2022-48340 · GlusterFS (dht translator, dht_setxattr_mds_cbk)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.