gpp_maybe
Security update for slurm
SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-314
This update for slurm fixes the following issues: Security fixes: - CVE-2023-41914: Prevent filesystem race conditions that could let an attacker take control of an arbitrary file, or remove entire directories' contents. (bsc#1216207) - CVE-2023-49933: Prevent message extension attacks that could bypass the message hash. (bsc#1218046) - CVE-2023-49936: Prevent NULL pointer dereference on `size_valp` overflow. (bsc#1218050) - CVE-2023-49937: Prevent double-xfree() on error in `_unpack_node_reg_resp()`. (bsc#1218051) - CVE-2023-49938: Prevent modified `sbcast` RPCs from opening a file with the wrong group permissions. (bsc#1218053) Other fixes: - Add missing service file for slurmrestd (bsc#1217711). - Fix slurm upgrading to incompatible versions (bsc#1216869).
-
Release DateFeb 2 2024
-
ReferencesBugzilla: 1216207, 1218051, 1218046, 1218050, 1218053, 1217711, 1216869, 1208810
CVEs: CVE-2023-49933, CVE-2023-49936, CVE-2023-41914, CVE-2023-49938, CVE-2023-49937 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Package Hub 15.5 ppc64le
-
Packageslibslurm36
Libraries for SLURMslurm20.11.9-150400.3.3.1 lock rpm
Simple Linux Utility for Resource Management20.11.9-150400.3.3.1 lock src