Database/Control plane, storage & DevOps

IBM Storage Scale Container Native Storage Access (pod security context): MULTI-TENANT ISOLATION: a local user in a
Impact
MULTI-TENANT ISOLATION: a local user in a CNSA-served container escalates to privileged access on the host node when security contexts are not set as intended. Owning the GPU node means owning every other tenant's container on it.
Who can reach it
Execution inside a container on a node running Storage Scale CNSA 5.1.2.1 through 5.1.6.1 where the security context is left at its permissive default.
What to do
Upgrade CNSA to the fixed level, and independently enforce restrictive pod security standards so the driver's containers cannot request host privileges. Verify by inspecting the running security context, not the chart defaults.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.