One low-privilege Dell CSM custom resource can compromise every Kubernetes node as root.
Dell Container Storage Modules, Kubernetes control software that connects clusters to Dell storage systems.
The attacker needs a Kubernetes identity permitted to submit a ContainerStorageModule custom resource.
Detail and 1 source
The privileged operator reconciles attacker-controlled resource data without preserving the caller’s privilege boundary, reaching root across all cluster nodes.
Dell has published a remediated CSM release, while pre-fix releases remain available and unrevoked.
The reach is cluster-wide, but only deployments delegating this uncommon resource permission expose the path.