Database/Control plane, storage & DevOps

IBM Spectrum Scale Container Native Storage Access: A local user obtains root privileges through the Spectrum Scale
Impact
A local user obtains root privileges through the Spectrum Scale container-native storage layer. Root on a node that mounts the shared training filesystem means access to whatever that node can see — which on a GPFS cluster is typically a very large namespace shared across tenants. Companion issue CVE-2022-43831 is the same shape via missing security-context settings.
Who can reach it
Local user on a node running Container Native Storage Access 5.1.2.1 through 5.1.6.0.
What to do
Upgrade past 5.1.6.0 (rolling). Independently, enforce restrictive Kubernetes security contexts on the storage-access pods — a manifest change you can apply immediately and that closes the CVE-2022-43831 variant on its own.
References
Related entries
- ConnectWise ScreenConnect: Path traversal enabling remote code executionCVE-2024-1708 · ConnectWise ScreenConnectHigh
- AMD Graphics Driver - crafted pointer leading to arbitrary writes: A specially crafted pointer passed to the AMDCVE-2024-36352 · AMD Graphics Driver - crafted pointer leading to arbitrary writesHigh
- Dell CloudLink (command injection): Command injection giving a privileged user full control of the CloudLink systemCVE-2025-30479 · Dell CloudLink (command injection)High
- Dell CloudLink (console command injection): Command injection from the console giving shell accessCVE-2025-45379 · Dell CloudLink (console command injection)High
- Renovate (kustomize manager): chart names are injected into helm pull commands, running attacker shell commandsCVE-2026-76229 · Renovate (kustomize manager, helm pull)High
- Renovate (helmv3 manager): repository value from Chart.yaml is injected into helm registry login commandsCVE-2026-76232 · Renovate (helmv3 manager, helm registry login)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.