Database/Control plane, storage & DevOps

IBM Spectrum Scale Container Native Storage Access (CSI volume handling): Anyone who can create a pod plus a PV/PVC
Impact
Anyone who can create a pod plus a PV/PVC reads files outside their own volume, including files on the host filesystem. On a shared Kubernetes GPU cluster that is a straight escape from a namespace's storage to everyone else's data and to node secrets.
Who can reach it
Kubernetes API access sufficient to create pods and persistent volume claims in any namespace served by Storage Scale CNSA 5.1. That is the normal permission set handed to a tenant team.
What to do
Upgrade Storage Scale CNSA to the fixed level in IBM's bulletin and roll the driver pods. Then check whether tenants actually need PV creation rights, or whether pre-provisioned volumes bound by an admin would do.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.