USN-8236-1
Dashboard / Vulnerabilities / USN-8236-1
USN-8236-1
Summary: slurm-wlm vulnerabilities
Details: It was discovered that Slurm did not correctly handle certain file system operations. An attacker could possibly use this issue to modify files or leak sensitive information. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-41914) Ryan Hall discovered that Slurm did not correctly enforce certain message integrity checks. An attacker could possibly use this issue to bypass integrity checks. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-49933) Ryan Hall discovered that Slurm did not correctly handle certain memory operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-49937) Ryan Hall discovered that Slurm did not correctly handle certain access control mechanisms. An attacker could possibly use this issue to modify files or leak sensitive information. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-49938) It was discovered that Slurm did not correctly handle user promotion. An attacker could possibly use this issue to promote themselves to an administrator. (CVE-2025-43904)
References: https://ubuntu.com/security/notices/USN-8236-1, https://ubuntu.com/security/CVE-2023-41914, https://ubuntu.com/security/CVE-2023-49933, https://ubuntu.com/security/CVE-2023-49937, https://ubuntu.com/security/CVE-2023-49938, https://ubuntu.com/security/CVE-2025-43904
Affected packages
Package
Name: slurm-wlm
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-apps/jammy
Affected ranges
Type: ECOSYSTEM
Events:
