SUSE-SU-2018:0987-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0987-1
SUSE-SU-2018:0987-1
Summary: Security update for slurm
Details: This update for slurm fixes the following issues: - Fix interaction with systemd: systemd expects that a daemonizing process doesn't go away until the PID file with it PID of the daemon has bee written (bsc#1084125). - Make sure systemd services get restarted only when all packages are in a consistent state, not in the middle of an 'update' transaction (bsc#1088693). Since the %postun scripts that run on update are from the old package they cannot be changed - thus we work around the restart breakage. - CVE-2018-7033: Fixed security issue in accounting_storage/mysql plugin by always escaping strings within the slurmdbd (bsc#1085240).
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180987-1/, https://bugzilla.suse.com/1084125, https://bugzilla.suse.com/1085240, https://bugzilla.suse.com/1088693, https://www.suse.com/security/cve/CVE-2018-7033
Affected packages
Package
Name: slurm
Purl: pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012
Affected ranges
Type: ECOSYSTEM
Events:
