GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum Scale mmfsd daemon (RPC request handling): A local attacker floods mmfsd with RPC requests and crashes it

CVE-2020-4491Control plane, storage & DevOpscurated

Impact

A local attacker floods mmfsd with RPC requests and crashes it, taking the filesystem away from every workload on that node. Repeatable, so it is a persistent denial of storage rather than a one-shot crash.

Who can reach it

Local account on a node running Spectrum Scale 4.2.x up to 4.2.3.22 or 5.0.x up to 5.0.5. No privileges beyond being able to issue RPCs to the local daemon.

What to do

Upgrade to 4.2.3.23 / 5.0.5.1 or later. There is no configuration workaround that keeps the daemon reachable to legitimate clients while blocking this, so the patch is the fix.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.