Database/Control plane, storage & DevOps

IBM Spectrum Scale / Storage Scale Container Native Storage Access: Programs running inside a container can overcome
Impact
Programs running inside a container can overcome the isolation mechanism of IBM Spectrum Scale Container Native Storage Access. Spectrum Scale (GPFS) is one of the two or three filesystems that actually keep up with large training clusters, and the container-native access layer is how Kubernetes-scheduled GPU jobs mount it. An isolation escape here means one tenant's pod reaching outside its intended storage boundary on shared cluster storage.
Who can reach it
A process inside a container that has Spectrum Scale container-native storage access — i.e. any tenant workload with a mounted volume.
What to do
Upgrade Container Native Storage Access past 5.1.6.0. This is a rolling upgrade of the storage-access DaemonSet/operator; pods remount as it rolls, so drain latency-sensitive jobs. No filesystem downtime, but plan for I/O stalls during the roll.
References
Related entries
- Linux octeontx2-af (VF rx-mode affecting PF promiscuous state): A VF setting its receive mode causes the *physicalCVE-2026-72312 · Linux octeontx2-af (VF rx-mode affecting PF promiscuous state)High
- Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingCVE-2015-2291 · Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingHigh
- IBM Spectrum Scale daemon (GSKit cryptographic library dependency): A local attacker takes control of the SpectrumCVE-2018-1431 · IBM Spectrum Scale daemon (GSKit cryptographic library dependency)High
- Arista CloudVision Portal (Configlet Builder API): A read-only CloudVision user escapes their permissions throughCVE-2019-18181 · Arista CloudVision Portal (Configlet Builder API)High
- MUNGE (SUSE/openSUSE packaging): The munge package's install scripts follow symlinks, so a local attacker who controlsCVE-2019-3691 · MUNGE (SUSE/openSUSE packaging)High
- IBM Spectrum Scale administrative command path: A local unprivileged user becomes root on a Storage Scale node byCVE-2019-4558 · IBM Spectrum Scale administrative command pathHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.