Database/Control plane, storage & DevOps
Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191: Use-after-free
Impact
Use-after-free in the VROC software giving an authenticated local user privilege escalation, followed by a run of access-control, default-permission and path-traversal escalations in later VROC releases. VROC is the software RAID layer sitting directly on NVMe on Xeon platforms - it is in the storage path for boot volumes and local scratch on many server designs. A local escalation here is a tenant-to-root path on any node where VROC is installed, and root on the node is the gateway to the whole firmware stack below it. The recurring pattern across four advisories is the useful signal: this component has a weak security history and should not be left installed where it is not needed.
Who can reach it
Authenticated local user on the host with the VROC software installed.
What to do
Update VROC to 8.6.0.1191 or later (or the latest available for your platform) via the OEM's storage software package - Dell, HPE, Lenovo and Supermicro all redistribute it. Software update, so no firmware flash, but a reboot is typical. The better move for most GPU fleets: if you are not actually using VROC RAID, uninstall it rather than patch it - it is frequently present in golden images purely because it came with the platform driver bundle, and each release has brought a new local escalation.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.