GPU VulnDB

Database/Control plane, storage & DevOps

IBM Storage Scale Container Native Storage Access (namespace boundary): TENANT ISOLATION: a local attacker can initiate

CVE-2022-41737Control plane, storage & DevOpscurated

Impact

TENANT ISOLATION: a local attacker can initiate connections from a container outside its current namespace. Network-namespace escape from a storage-access container is a direct route from one tenant's pod onto networks the pod was never meant to touch — including, on most cluster designs, the storage back-end network where authentication is weak because it is assumed to be private.

Who can reach it

A local attacker inside a container using Storage Scale container-native access, versions 5.1.2.1 through 5.1.7.0.

What to do

Upgrade Container Native Storage Access past 5.1.7.0 — rolling operator/DaemonSet upgrade. Companion issue CVE-2022-41738 allows connections *into* containers from external networks; both are closed by the same upgrade path. Also treat the storage back-end network as authenticated rather than trusted, which is an architectural change and the durable answer.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.