Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
10b55693 by Salvatore Bonaccorso at 2026-09-07T06:53:04+02:00
Track fixed version for slurm-wlm issues via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3098,25 +3098,25 @@ CVE-2026-XXXX [Out-of-bounds read in RGB-YCbCr
identity-matrix colour conversion
- libheif 1.23.3-1
NOTE:
https://github.com/strukturag/libheif/security/advisories/GHSA-9rj8-5mp5-26c9
CVE-2026-65107 [Fix sbcast shared objects skipping credential verification,
Fix possible slurmd crash on invalid sbcast filenames]
- - slurm-wlm <unfixed> (bug #1146563)
+ - slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65108 [Fix a slurmstepd stack overflow when a job environment
contains an oversized SPANK option variable]
- - slurm-wlm <unfixed> (bug #1146563)
+ - slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65109 [Fix slurmstepd removing files outside the container spool
directory when cleaning up an OCI containe, Fix slurmstepd leaving OCI
container spool directories behind when ContainerPath contains a task id
pattern]
- - slurm-wlm <unfixed> (bug #1146563)
+ - slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65138 [Fix heap over-read when unpacking a malformed forward data RPC
in slurmd. Fix a slurmd crash when handling a malformed forward data RPC with a
missing socket address]
- - slurm-wlm <unfixed> (bug #1146563)
+ - slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65139 [Fix various issues in unsafe operation/queries to the slurmdbd]
- - slurm-wlm <unfixed> (bug #1146563)
+ - slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65140 [Fix a privilege escalation where an operator could alter
Administrator accounts through the accounting database]
- - slurm-wlm <unfixed> (bug #1146563)
+ - slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-65165 [Fix various issues around job steps and node count
discrepancies]
- - slurm-wlm <unfixed> (bug #1146563)
+ - slurm-wlm 26.05.4-1 (bug #1146563)
NOTE:
https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
CVE-2026-76642 (util-linux versions through 2.41.5 and 2.42.2 fail to check
mount help ...)
- util-linux 2.42.3-1
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/10b55693b8e24520b9d31b1d332032f47c1c8e1b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/10b55693b8e24520b9d31b1d332032f47c1c8e1b
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits