GPU VulnDB

Database/Control plane, storage & DevOps

IBM Spectrum Scale core component (format string handling): A user with a shell on any node that runs Storage Scale

CVE-2021-29740Control plane, storage & DevOpscurated

Impact

A user with a shell on any node that runs Storage Scale gets arbitrary code execution inside the core storage process, which runs privileged. From there the whole node's view of the filesystem is under attacker control.

Who can reach it

Local, low-privileged account on a node running the Storage Scale core component - in practice any compute node with the client mounted, including a tenant's own job container if it can reach the host.

What to do

Apply the Storage Scale efix listed in IBM's bulletin for the 5.0.x / 5.1.0.x line and restart the daemon on each node in a rolling fashion. Audit which non-admin accounts have local shells on nodes that run the core component.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.