Database/Control plane, storage & DevOps
HTCondor (condor_schedd, GSI/VOMS extension parsing): An authenticated user crashes the schedd by feeding it malformed
CVSS 6.5CVE-2017-16816Control plane, storage & DevOpsHTCONDOR-2017-0001curated
Impact
An authenticated user crashes the schedd by feeding it malformed GSI/VOMS extensions. The schedd owns the job queue, so while it is down nobody in the pool can submit, query or reap jobs and the GPUs behind it drain.
Who can reach it
A remote authenticated user of the pool, on a schedd configured to use GSI with VOMS extensions.
What to do
Upgrade to HTCondor 8.6.8 or 8.7.5 and restart condor_schedd. GSI is deprecated in modern HTCondor - moving the pool to IDTOKENS or SSL removes this code path entirely.
References
Related entries
- GlusterFS (dict_unserialize): A negative key length in a serialized dict makes the server read memory from elsewhere inCVE-2018-10911 · GlusterFS (dict_unserialize)Medium
- Ceph CephX authentication protocol: The CephX signature calculation can be bypassed, so an on-path attacker can alterCVE-2018-1129 · Ceph CephX authentication protocolMedium
- Intel Core and Xeon CPUs - INTEL-SA-00210: This one is availability, not confidentiality, and it is the mostCVE-2018-12207 · Intel Core and Xeon CPUs - INTEL-SA-00210Medium
- Nouveau display driver (in-tree Linux nouveau, NV117): Remote denial of service against a workstation or node runningCVE-2018-3979 · Nouveau display driver (in-tree Linux nouveau, NV117)Medium
- Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270: Same class of in-flight data leakCVE-2019-11135 · Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270Medium
- Ceph RGW: HTTP header injection via a newline in the CORS ExposeHeader tagCVE-2021-3524 · Ceph RGWMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.