GPU VulnDB

Database/Control plane, storage & DevOps

HTCondor (condor_schedd, GSI/VOMS extension parsing): An authenticated user crashes the schedd by feeding it malformed

CVE-2017-16816Control plane, storage & DevOpsHTCONDOR-2017-0001curated

Impact

An authenticated user crashes the schedd by feeding it malformed GSI/VOMS extensions. The schedd owns the job queue, so while it is down nobody in the pool can submit, query or reap jobs and the GPUs behind it drain.

Who can reach it

A remote authenticated user of the pool, on a schedd configured to use GSI with VOMS extensions.

What to do

Upgrade to HTCondor 8.6.8 or 8.7.5 and restart condor_schedd. GSI is deprecated in modern HTCondor - moving the pool to IDTOKENS or SSL removes this code path entirely.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.