GPU VulnDB

Database/Control plane, storage & DevOps

IBM Storage Scale Container Native Storage Access (network namespace exposure): MULTI-TENANT ISOLATION: hosts outside

CVE-2022-41738Control plane, storage & DevOpscurated

Impact

MULTI-TENANT ISOLATION: hosts outside the cluster can open connections directly to CNSA containers, bypassing whatever ingress policy the operator thought was in force. Container-internal services that were only ever meant to be cluster-local become externally addressable.

Who can reach it

Network position outside the Kubernetes cluster with a route to the node network. No credentials required.

What to do

Upgrade Storage Scale CNSA to the fixed level from IBM's bulletin, then confirm with an external port scan that the driver containers are no longer answering. Add explicit NetworkPolicy denying ingress to the storage namespace as defence in depth.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.