GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum Scale container image (command execution): A local attacker runs arbitrary commands inside the Spectrum

CVE-2022-43867Control plane, storage & DevOpscurated

Impact

A local attacker runs arbitrary commands inside the Spectrum Scale container, which is the process that brokers filesystem access for everything scheduled on that node.

Who can reach it

Local, low-privileged access to a node running Spectrum Scale 5.1.0.1 through 5.1.4.1 in container form.

What to do

Pull the fixed Storage Scale container image per IBM's bulletin and redeploy the DaemonSet. Confirm the running image digest afterwards rather than trusting the tag.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.