Database/Control plane, storage & DevOps

IBM Spectrum Scale container image (command execution): A local attacker runs arbitrary commands inside the Spectrum
CVSS 7.8CVE-2022-43867Control plane, storage & DevOpscurated
Impact
A local attacker runs arbitrary commands inside the Spectrum Scale container, which is the process that brokers filesystem access for everything scheduled on that node.
Who can reach it
Local, low-privileged access to a node running Spectrum Scale 5.1.0.1 through 5.1.4.1 in container form.
What to do
Pull the fixed Storage Scale container image per IBM's bulletin and redeploy the DaemonSet. Confirm the running image digest afterwards rather than trusting the tag.
References
Related entries
- AMD SMM - memory corruption (AMD-SB-4003): Memory corruption reachable in System Management Mode. Same class as theCVE-2023-20555 · AMD SMM - memory corruption (AMD-SB-4003)High
- AMD Radeon Graphics driver - IOCTL granting arbitrary I/O port and physical memory access: Improper privilegeCVE-2023-20598 · AMD Radeon Graphics driver - IOCTL granting arbitrary I/O port and physical memory accessHigh
- HPE OneView (command injection with local privilege escalation): A low-privileged local user on the OneView applianceCVE-2023-50274 · HPE OneView (command injection with local privilege escalation)High
- OpenVPN: Stack overflow in the interactive serviceCVE-2024-27459 · OpenVPNHigh
- Intel QuickAssist Technology (QAT) software and driversCVE-2024-31858 · Intel QuickAssist Technology (QAT) software and drivers - QAT software before 2.2.0, with a 2025 batch through 2.6.0High
- IBM Storage Scale GUI (local privilege escalation): A local privilege escalation in the Storage Scale GUI availableCVE-2024-31891 · IBM Storage Scale GUI (local privilege escalation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.