Source: slurm-wlm
Version: 26.05.3-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for slurm-wlm.

CVE-2026-65107[0]:
| Fix sbcast shared objects skipping credential verification, Fix
| possible slurmd crash on invalid sbcast filenames


CVE-2026-65108[1]:
| Fix a slurmstepd stack overflow when a job environment contains an
| oversized SPANK option variable


CVE-2026-65109[2]:
| Fix slurmstepd removing files outside the container spool directory
| when cleaning up an OCI containe, Fix slurmstepd leaving OCI container
| spool directories behind when ContainerPath contains a task id pattern


CVE-2026-65138[3]:
| Fix heap over-read when unpacking a malformed forward data RPC in
| slurmd. Fix a slurmd crash when handling a malformed forward data RPC
| with a missing socket address


CVE-2026-65139[4]:
| Fix various issues in unsafe operation/queries to the slurmdbd


CVE-2026-65140[5]:
| Fix a privilege escalation where an operator could alter Administrator
| accounts through the accounting database


CVE-2026-65165[6]:
| Fix various issues around job steps and node count discrepancies


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-65107
    https://www.cve.org/CVERecord?id=CVE-2026-65107
[1] https://security-tracker.debian.org/tracker/CVE-2026-65108
    https://www.cve.org/CVERecord?id=CVE-2026-65108
[2] https://security-tracker.debian.org/tracker/CVE-2026-65109
    https://www.cve.org/CVERecord?id=CVE-2026-65109
[3] https://security-tracker.debian.org/tracker/CVE-2026-65138
    https://www.cve.org/CVERecord?id=CVE-2026-65138
[4] https://security-tracker.debian.org/tracker/CVE-2026-65139
    https://www.cve.org/CVERecord?id=CVE-2026-65139
[5] https://security-tracker.debian.org/tracker/CVE-2026-65140
    https://www.cve.org/CVERecord?id=CVE-2026-65140
[6] https://security-tracker.debian.org/tracker/CVE-2026-65165
    https://www.cve.org/CVERecord?id=CVE-2026-65165
[7] 
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to