Database/Container, Kubernetes & orchestration
Intel Device Plugins for Kubernetes (GPU/accelerator device plugin, access control): Improper access control in Intel's
Impact
Improper access control in Intel's Kubernetes device plugins lets a privileged local user deny service on the node. Because the device plugin is what advertises and allocates accelerators to the kubelet, knocking it over means the node stops offering its accelerators and scheduled workloads lose their allocation.
Who can reach it
A privileged user with local access to a node running Intel Device Plugins for Kubernetes before 0.32.0.
What to do
Upgrade the Intel device plugin DaemonSet to 0.32.0 or later and let it roll across the nodes. The DaemonSet restart is enough - no drain or reboot - but confirm accelerator capacity re-registers on each node after the rollout.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.