SUSE-SU-2024:0284-1
Dashboard / Vulnerabilities / SUSE-SU-2024:0284-1
SUSE-SU-2024:0284-1
Summary: Security update for slurm
Details: This update for slurm fixes the following issues: Update to slurm 23.02.6: Security fixes: - CVE-2023-49933: Prevent message extension attacks that could bypass the message hash. (bsc#1218046) - CVE-2023-49935: Prevent message hash bypass in slurmd which can allow an attacker to reuse root-level MUNGE tokens and escalate permissions. (bsc#1218049) - CVE-2023-49936: Prevent NULL pointer dereference on `size_valp` overflow. (bsc#1218050) - CVE-2023-49937: Prevent double-xfree() on error in `_unpack_node_reg_resp()`. (bsc#1218051) - CVE-2023-49938: Prevent modified `sbcast` RPCs from opening a file with the wrong group permissions. (bsc#1218053) Other fixes: - Add missing service file for slurmrestd (bsc#1217711). - Fix slurm upgrading to incompatible versions (bsc#1216869).
References: https://www.suse.com/support/update/announcement/2024/suse-su-20240284-1/, https://bugzilla.suse.com/1216869, https://bugzilla.suse.com/1217711, https://bugzilla.suse.com/1218046, https://bugzilla.suse.com/1218049, https://bugzilla.suse.com/1218050, https://bugzilla.suse.com/1218051, https://bugzilla.suse.com/1218053, https://www.suse.com/security/cve/CVE-2023-49933, https://www.suse.com/security/cve/CVE-2023-49935, https://www.suse.com/security/cve/CVE-2023-49936, https://www.suse.com/security/cve/CVE-2023-49937, https://www.suse.com/security/cve/CVE-2023-49938
Affected packages
Package
Name: slurm
Purl: pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
