Skip to finding
important · Edge

One low-privilege Dell CSM custom resource can compromise every Kubernetes node as root.

Affects

Dell Container Storage Modules, Kubernetes control software that connects clusters to Dell storage systems.

The attacker needs a Kubernetes identity permitted to submit a ContainerStorageModule custom resource.

Detail and 1 source

The privileged operator reconciles attacker-controlled resource data without preserving the caller’s privilege boundary, reaching root across all cluster nodes.

Dell has published a remediated CSM release, while pre-fix releases remain available and unrevoked.

The reach is cluster-wide, but only deployments delegating this uncommon resource permission expose the path.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026