GPU VulnDB

Database/Control plane, storage & DevOps

IBM Storage Scale SMB protocol stack (inherited ACL handling): Files created or modified over SMB inherit permissions

CVE-2025-36104Control plane, storage & DevOpscurated

Impact

Files created or modified over SMB inherit permissions that are wider than intended, so an authenticated user reads data they were never granted. On a mixed-protocol cluster this quietly opens one tenant's directories to another.

Who can reach it

Any authenticated SMB client of a Storage Scale 5.2.3.0 or 5.2.3.1 cluster where directories use inherited ACLs.

What to do

Apply the fix from IBM's bulletin, then audit effective ACLs on every directory that was created or modified through SMB while the affected versions ran - the upgrade corrects behaviour going forward but does not repair permissions already written.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.