GPU VulnDB

Database/Control plane, storage & DevOps

IBM Storage Scale Container Native Storage Access (pod security context): MULTI-TENANT ISOLATION: a local user in a

CVE-2022-43831Control plane, storage & DevOpscurated

Impact

MULTI-TENANT ISOLATION: a local user in a CNSA-served container escalates to privileged access on the host node when security contexts are not set as intended. Owning the GPU node means owning every other tenant's container on it.

Who can reach it

Execution inside a container on a node running Storage Scale CNSA 5.1.2.1 through 5.1.6.1 where the security context is left at its permissive default.

What to do

Upgrade CNSA to the fixed level, and independently enforce restrictive pod security standards so the driver's containers cannot request host privileges. Verify by inspecting the running security context, not the chart defaults.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.