Database/Control plane, storage & DevOps

IBM Storage Scale Container Native Storage Access (pod security context): A local user in a CNSA-served container
Impact
A local user in a CNSA-served container escalates to privileged access on the host node when security contexts are not set as intended. Owning the GPU node means owning every other tenant's container on it.
Who can reach it
Execution inside a container on a node running Storage Scale CNSA 5.1.2.1 through 5.1.6.1 where the security context is left at its permissive default.
What to do
Upgrade CNSA to the fixed level, and independently enforce restrictive pod security standards so the driver's containers cannot request host privileges. Verify by inspecting the running security context, not the chart defaults.
References
Related entries
- IBM Spectrum Scale container image (command execution): A local attacker runs arbitrary commands inside the SpectrumCVE-2022-43867 · IBM Spectrum Scale container image (command execution)High
- AMD SMM - memory corruption (AMD-SB-4003): Memory corruption reachable in System Management Mode. Same class as theCVE-2023-20555 · AMD SMM - memory corruption (AMD-SB-4003)High
- AMD Radeon Graphics driver - IOCTL granting arbitrary I/O port and physical memory access: Improper privilegeCVE-2023-20598 · AMD Radeon Graphics driver - IOCTL granting arbitrary I/O port and physical memory accessHigh
- HPE OneView (command injection with local privilege escalation): A low-privileged local user on the OneView applianceCVE-2023-50274 · HPE OneView (command injection with local privilege escalation)High
- OpenVPN: Stack overflow in the interactive serviceCVE-2024-27459 · OpenVPNHigh
- Intel QuickAssist Technology (QAT) software and driversCVE-2024-31858 · Intel QuickAssist Technology (QAT) software and drivers - QAT software before 2.2.0, with a 2025 batch through 2.6.0High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.