Source: slurm-wlm Version: 26.05.3-1 Severity: grave Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for slurm-wlm. CVE-2026-65107[0]: | Fix sbcast shared objects skipping credential verification, Fix | possible slurmd crash on invalid sbcast filenames CVE-2026-65108[1]: | Fix a slurmstepd stack overflow when a job environment contains an | oversized SPANK option variable CVE-2026-65109[2]: | Fix slurmstepd removing files outside the container spool directory | when cleaning up an OCI containe, Fix slurmstepd leaving OCI container | spool directories behind when ContainerPath contains a task id pattern CVE-2026-65138[3]: | Fix heap over-read when unpacking a malformed forward data RPC in | slurmd. Fix a slurmd crash when handling a malformed forward data RPC | with a missing socket address CVE-2026-65139[4]: | Fix various issues in unsafe operation/queries to the slurmdbd CVE-2026-65140[5]: | Fix a privilege escalation where an operator could alter Administrator | accounts through the accounting database CVE-2026-65165[6]: | Fix various issues around job steps and node count discrepancies If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-65107 https://www.cve.org/CVERecord?id=CVE-2026-65107 [1] https://security-tracker.debian.org/tracker/CVE-2026-65108 https://www.cve.org/CVERecord?id=CVE-2026-65108 [2] https://security-tracker.debian.org/tracker/CVE-2026-65109 https://www.cve.org/CVERecord?id=CVE-2026-65109 [3] https://security-tracker.debian.org/tracker/CVE-2026-65138 https://www.cve.org/CVERecord?id=CVE-2026-65138 [4] https://security-tracker.debian.org/tracker/CVE-2026-65139 https://www.cve.org/CVERecord?id=CVE-2026-65139 [5] https://security-tracker.debian.org/tracker/CVE-2026-65140 https://www.cve.org/CVERecord?id=CVE-2026-65140 [6] https://security-tracker.debian.org/tracker/CVE-2026-65165 https://www.cve.org/CVERecord?id=CVE-2026-65165 [7] https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

