GPU VulnDB

Database/AI/ML frameworks & serving

Pure Storage FlashArray key rotation logging (Rapid Data Locking): The Key Encryption Key is written to logs during

CVE-2025-2327AI/ML frameworks & servingcurated

Impact

The Key Encryption Key is written to logs during rotation when Rapid Data Locking is configured. Anyone who can read those logs - including whoever receives a support bundle - holds the key that protects data at rest on the array.

Who can reach it

Read access to FlashArray logs, or possession of a support bundle collected from an affected array with RDL enabled.

What to do

Upgrade Purity//FA to the fixed release, then rotate the KEK again on a patched version and destroy or recall any log set or support bundle collected while the flaw was present.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.