GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum Scale Local Read Only Cache (LROC): MULTI-TENANT ISOLATION: with LROC enabled, a read of one file can

CVE-2018-1993Control plane, storage & DevOpscurated

Impact

MULTI-TENANT ISOLATION: with LROC enabled, a read of one file can silently return the contents of a different file. A tenant reading its own dataset gets back bytes belonging to someone else, and a training job can ingest another tenant's data without anyone noticing.

Who can reach it

Any user able to read files on a node with LROC enabled. This is a correctness bug in the cache rather than an exploit chain, so it fires during ordinary I/O.

What to do

Upgrade to the fixed Spectrum Scale level. If an upgrade cannot happen right away, disable LROC on affected nodes - the performance loss is far cheaper than cross-tenant data bleed, and any data read while LROC was active should be treated as suspect.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.