CVE-2023-45085: When compute hosts are disabled and reenabled, they immediately transition to "ON", not "INIT"
An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without following the correct initialization process. In this instance, workloads may be scheduled on these nodes and deploy to a failed or erroneous state, which impacts the availability of these workloads that may be deployed during this time window.
This issue impacts HyperCloud versions from 2.0.0 to before 2.0.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45085?
CVE-2023-45085 is classified as a high severity vulnerability due to its potential impact on workload failures.
How do I fix CVE-2023-45085?
To fix CVE-2023-45085, ensure that compute nodes are properly initialized before scheduling workloads.
What versions are affected by CVE-2023-45085?
CVE-2023-45085 affects SoftIron HyperCloud versions between 2.0.0 and 2.0.3.
What is the impact of CVE-2023-45085 on SoftIron HyperCloud?
CVE-2023-45085 may lead to scheduled workloads deploying to a failed or erroneous state, affecting availability.
Is there a workaround for CVE-2023-45085?
A possible workaround for CVE-2023-45085 is to implement strict monitoring and control over node initialization processes.