Database/Control plane, storage & DevOps

Slurm (srun --uid): Srun --uid drops privileges in the wrong order, so a step launched through it can end up running
CVSS 7.5CVE-2019-19728Control plane, storage & DevOpscurated
Impact
Srun --uid drops privileges in the wrong order, so a step launched through it can end up running with more privilege than the target user should have. On a shared cluster this is a path from an admin-adjacent account to code execution as, or above, another tenant.
Who can reach it
A local user able to invoke srun with --uid on a login or submit node.
What to do
Upgrade to Slurm 18.08.9 or 19.05.5 and restart slurmctld and slurmd. If you cannot upgrade immediately, remove --uid from any operator tooling and wrapper scripts that run as root.
References
Related entries
- Lustre ptlrpc / mdt modules (client-driven server panic family): The head of a family of ten Lustre defectsCVE-2019-20423 · Lustre ptlrpc / mdt modules (client-driven server panic family)High
- Lustre (mdt module, mdt_object_remote): A client sends a packet with unvalidated fields and the metadata serverCVE-2019-20424 · Lustre (mdt module, mdt_object_remote)High
- Lustre (ptlrpc module): Out-of-bounds write in the RPC layer, reachable by a client that lies about packet field sizes.CVE-2019-20425 · Lustre (ptlrpc module)High
- Lustre (ptlrpc module): A second out-of-bounds access in ptlrpc triggered by unvalidated client packet fields, endingCVE-2019-20426 · Lustre (ptlrpc module)High
- Lustre (ptlrpc module): Out-of-bounds read in ptlrpc leading to a server panic. The read primitive also means serverCVE-2019-20428 · Lustre (ptlrpc module)High
- Lustre (ptlrpc module, lm_bufcount handling): A client that modifies the lm_bufcount field walks the server off the endCVE-2019-20429 · Lustre (ptlrpc module, lm_bufcount handling)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.