GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum Scale Container Native Storage Access: A local user obtains root privileges through the Spectrum Scale

CVE-2022-41736Control plane, storage & DevOpscurated

Impact

A local user obtains root privileges through the Spectrum Scale container-native storage layer. Root on a node that mounts the shared training filesystem means access to whatever that node can see — which on a GPFS cluster is typically a very large namespace shared across tenants. Companion issue CVE-2022-43831 is the same shape via missing security-context settings.

Who can reach it

Local user on a node running Container Native Storage Access 5.1.2.1 through 5.1.6.0.

What to do

Upgrade past 5.1.6.0 (rolling). Independently, enforce restrictive Kubernetes security contexts on the storage-access pods — a manifest change you can apply immediately and that closes the CVE-2022-43831 variant on its own.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.