Database/Control plane, storage & DevOps

IBM Storage Scale Container Native Storage Access (namespace boundary): A local attacker can initiate connections from
Impact
A local attacker can initiate connections from a container outside its current namespace. Network-namespace escape from a storage-access container is a direct route from one tenant's pod onto networks the pod was never meant to touch — including, on most cluster designs, the storage back-end network where authentication is weak because it is assumed to be private.
Who can reach it
A local attacker inside a container using Storage Scale container-native access, versions 5.1.2.1 through 5.1.7.0.
What to do
Upgrade Container Native Storage Access past 5.1.7.0 — rolling operator/DaemonSet upgrade. Companion issue CVE-2022-41738 allows connections *into* containers from external networks; both are closed by the same upgrade path. Also treat the storage back-end network as authenticated rather than trusted, which is an architectural change and the durable answer.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.