Database/Control plane, storage & DevOps

IBM Spectrum Scale Container Native Storage Access (CSI volume handling): Anyone who can create a pod plus a PV/PVC
Impact
Anyone who can create a pod plus a PV/PVC reads files outside their own volume, including files on the host filesystem. On a shared Kubernetes GPU cluster that is a straight escape from a namespace's storage to everyone else's data and to node secrets.
Who can reach it
Kubernetes API access sufficient to create pods and persistent volume claims in any namespace served by Storage Scale CNSA 5.1. That is the normal permission set handed to a tenant team.
What to do
Upgrade Storage Scale CNSA to the fixed level in IBM's bulletin and roll the driver pods. Then check whether tenants actually need PV creation rights, or whether pre-provisioned volumes bound by an admin would do.
References
Related entries
- AMD - overlap between segmented reverse map table (RMP) and SMM memory: Improper handling of overlap between theCVE-2025-0012 · AMD - overlap between segmented reverse map table (RMP) and SMM memoryMedium
- Motherboards from ASRock and its subsidiaries ASRockRack and ASRockInd built on Intel 500-series chipsetsCVE-2025-14304 · Motherboards from ASRock and its subsidiaries ASRockRack and ASRockInd built on Intel 500-series chipsetsMedium
- Argo CD: Secret values exposed in error messages and the diff view when an invalid Secret is syncedCVE-2025-23216 · Argo CDMedium
- Grafana Enterprise: SAML responses skip InResponseTo validation, allowing assertion replayCVE-2026-12704 · Grafana Enterprise SAML authentication (InResponseTo validation)Medium
- Grafana: unsanitized alert generatorURL runs attacker JavaScript in a viewing user's sessionCVE-2026-17033 · Grafana OSS (Alert Details 'See source' link, alert.generatorURL rendering)Medium
- GitLab CE/EE: Terraform state upload parameters let a project user read server files or DoS the instanceCVE-2026-3855 · GitLab CE/EE (Terraform state upload parameter validation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.