GPU VulnDB

Database/Control plane, storage & DevOps

Intel Virtual RAID on CPU (VROC) software before 7.7.6.1003, with follow-on issues through 8.6.0.1191: Use-after-free

CVE-2022-29919Control plane, storage & DevOpsINTEL-SA-00692CVE-2022-45112INTEL-SA-00846CVE-2023-31271INTEL-SA-00953CVE-2024-23489curated

Impact

Use-after-free in the VROC software giving an authenticated local user privilege escalation, followed by a run of access-control, default-permission and path-traversal escalations in later VROC releases. VROC is the software RAID layer sitting directly on NVMe on Xeon platforms - it is in the storage path for boot volumes and local scratch on many server designs. A local escalation here is a tenant-to-root path on any node where VROC is installed, and root on the node is the gateway to the whole firmware stack below it. The recurring pattern across four advisories is the useful signal: this component has a weak security history and should not be left installed where it is not needed.

Who can reach it

Authenticated local user on the host with the VROC software installed.

What to do

Update VROC to 8.6.0.1191 or later (or the latest available for your platform) via the OEM's storage software package - Dell, HPE, Lenovo and Supermicro all redistribute it. Software update, so no firmware flash, but a reboot is typical. The better move for most GPU fleets: if you are not actually using VROC RAID, uninstall it rather than patch it - it is frequently present in golden images purely because it came with the platform driver bundle, and each release has brought a new local escalation.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.