Database/Control plane, storage & DevOps

Slurm (slurmdbd, sacctmgr archive load): A second SQL injection path into SlurmDBD, this one through the 'sacctmgr
Impact
A second SQL injection path into SlurmDBD, this one through the 'sacctmgr archive load' path where strings were not escaped before hitting the database. Same consequence as the 2018 injection - arbitrary read and write of the accounting database that defines account membership, QOS caps and fairshare, which is the data structure the scheduler uses to decide whose jobs get GPUs.
Who can reach it
Anything that can reach the slurmdbd RPC port, typically the login nodes and the controller. The archive-load path is what an operator or an account coordinator invokes to reload archived accounting data.
What to do
Upgrade to Slurm 18.08.8 or 19.05.1 and restart slurmdbd. SchedMD published fixes only for the then-supported 18.08 and 19.05 lines and warned that earlier versions carry similar flaws with no patch, so anything older has to move forward. Restrict slurmdbd's listener to the controller and admin hosts rather than the whole login-node subnet while you are in there.
References
Related entries
- HTCondor (condor_startd, condor_schedd, condor_shadow): One CVE covering four separate authentication failures theCVE-2019-18823 · HTCondor (condor_startd, condor_schedd, condor_shadow)Critical
- Lustre ptlrpc module (server-side client packet validation): A Lustre client can send a crafted RPC that overflows aCVE-2019-20427 · Lustre ptlrpc module (server-side client packet validation)Critical
- NetApp ONTAP Select Deploy administration utility (HTTP service): An unauthenticated attacker performs administrativeCVE-2019-5504 · NetApp ONTAP Select Deploy administration utility (HTTP service)Critical
- NetApp ONTAP Select Deploy administration utility (credential transport): Deploy sends its credentials in plaintext, soCVE-2019-5505 · NetApp ONTAP Select Deploy administration utility (credential transport)Critical
- NetApp ONTAP Select Deploy administration utility (code injection): An unauthenticated remote attacker injects code andCVE-2019-5509 · NetApp ONTAP Select Deploy administration utility (code injection)Critical
- Slurm (32-bit RPC handling): Memory corruption on 32-bit Slurm builds reachable from a crafted RPC, up to control ofCVE-2019-6438 · Slurm (32-bit RPC handling)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.