{"id":"USN-6458-1","summary":"slurm-llnl, slurm-wlm vulnerabilities","details":"It was discovered that Slurm did not properly handle credential\nmanagement, which could allow an unprivileged user to impersonate the\nSlurmUser account. An attacker could possibly use this issue to execute\narbitrary code as the root user. (CVE-2022-29500)\n\nIt was discovered that Slurm did not properly handle access control when\ndealing with RPC traffic through PMI2 and PMIx, which could allow an\nunprivileged user to send data to an arbitrary unix socket in the host.\nAn attacker could possibly use this issue to execute arbitrary code as\nthe root user. (CVE-2022-29501)\n\nIt was discovered that Slurm did not properly handle validation logic when\nprocessing input and output data with the srun client, which could lead to\nthe interception of process I/O. An attacker could possibly use this issue\nto expose sensitive information or execute arbitrary code. This issue only\naffected Ubuntu 22.04 LTS. (CVE-2022-29502)\n","modified":"2026-04-22T10:41:31.714463Z","published":"2023-10-30T11:20:24Z","related":["UBUNTU-CVE-2022-29500","UBUNTU-CVE-2022-29501","UBUNTU-CVE-2022-29502"],"upstream":["CVE-2022-29500","CVE-2022-29501","CVE-2022-29502","UBUNTU-CVE-2022-29500","UBUNTU-CVE-2022-29501","UBUNTU-CVE-2022-29502"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6458-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-29500"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-29501"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-29502"}],"affected":[{"package":{"name":"slurm-llnl","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/slurm-llnl@19.05.5-1ubuntu0.1~esm2?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"19.05.5-1ubuntu0.1~esm2"}]}],"versions":["19.05.3.2-2","19.05.3.2-2build1","19.05.5-1","19.05.5-1ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"libpam-slurm","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"libpam-slurm-adopt","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"libpmi0","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"libpmi2-0","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"libslurm-perl","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"libslurm34","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"libslurmdb-perl","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"slurm-client","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"slurm-client-emulator","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"slurm-wlm","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"slurm-wlm-basic-plugins","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"slurm-wlm-emulator","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"slurm-wlm-torque","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"slurmctld","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"slurmd","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"slurmdbd","binary_version":"19.05.5-1ubuntu0.1~esm2"},{"binary_name":"sview","binary_version":"19.05.5-1ubuntu0.1~esm2"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6458-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[{"id":"CVE-2022-29500","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2022-29501","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]}]}}},{"package":{"name":"slurm-wlm","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/slurm-wlm@21.08.5-2ubuntu1+esm1?arch=source&distro=esm-apps/jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"21.08.5-2ubuntu1+esm1"}]}],"versions":["20.11.7+really20.11.4-2","21.08.5-1","21.08.5-1.1","21.08.5-2","21.08.5-2ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"libpam-slurm","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"libpam-slurm-adopt","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"libpmi0","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"libpmi2-0","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"libslurm-perl","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"libslurm37","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"libslurmdb-perl","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"slurm-client","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"slurm-client-emulator","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"slurm-wlm","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"slurm-wlm-basic-plugins","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"slurm-wlm-emulator","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"slurm-wlm-torque","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"slurmctld","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"slurmd","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"slurmdbd","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"slurmrestd","binary_version":"21.08.5-2ubuntu1+esm1"},{"binary_name":"sview","binary_version":"21.08.5-2ubuntu1+esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6458-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:22.04:LTS","cves":[{"id":"CVE-2022-29500","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2022-29501","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2022-29502","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}]}}}],"schema_version":"1.7.5"}