Database/Control plane, storage & DevOps

IBM Storage Scale Container Native Storage Access (namespace boundary): A local attacker can initiate connections from
Impact
A local attacker can initiate connections from a container outside its current namespace. Network-namespace escape from a storage-access container is a direct route from one tenant's pod onto networks the pod was never meant to touch — including, on most cluster designs, the storage back-end network where authentication is weak because it is assumed to be private.
Who can reach it
A local attacker inside a container using Storage Scale container-native access, versions 5.1.2.1 through 5.1.7.0.
What to do
Upgrade Container Native Storage Access past 5.1.7.0 — rolling operator/DaemonSet upgrade. Companion issue CVE-2022-41738 allows connections *into* containers from external networks; both are closed by the same upgrade path. Also treat the storage back-end network as authenticated rather than trusted, which is an architectural change and the durable answer.
References
Related entries
- SK Hynix DDR5 DIMMs (manufactured 2021-01 through 2024-12): Rowhammer bit flips on DDR5, which had been assumed outCVE-2025-6202 · SK Hynix DDR5 DIMMs (manufactured 2021-01 through 2024-12)High
- AMD Zen 5 RDSEED (16-bit and 32-bit variants): On Zen 5, the 16-bit and 32-bit forms of RDSEED return zero far moreCVE-2025-68313 · AMD Zen 5 RDSEED (16-bit and 32-bit variants)High
- Grafana: Auth Proxy cache key collision authenticates a low-privileged user as an administratorCVE-2026-14199 · Grafana Auth Proxy authentication (identity cache key built by concatenation)High
- GitLab EE: missing authorization lets a low-privileged member change restricted project settingsCVE-2026-16494 · GitLab EE (project update endpoint authorization)High
- Grafana: alert rule marked as a server-side expression bypasses datasource query authorizationCVE-2026-17183 · Grafana (alert rule server-side expression datasource authorization)High
- GitLab: unauthenticated GraphQL mutations executed via GET through multiplex query handlingCVE-2026-19650 · GitLab CE/EE (GraphQL multiplex query handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.