Database/Control plane, storage & DevOps
MUNGE (SUSE/openSUSE packaging): The munge package's install scripts follow symlinks, so a local attacker who controls
Impact
The munge package's install scripts follow symlinks, so a local attacker who controls the munge account can get root-owned files written to paths of their choosing. On a Slurm cluster the munge account is present on every node, which makes this a broad local escalation surface rather than a one-host issue.
Who can reach it
Local attacker with control of the munge user on a SUSE Linux Enterprise 15 or openSUSE host, exploited during package install or upgrade.
What to do
Apply the SUSE munge package update on all nodes. Not applicable if you build MUNGE from source or run a non-SUSE distro.
References
Related entries
- IBM Spectrum Scale administrative command path: A local unprivileged user becomes root on a Storage Scale node byCVE-2019-4558 · IBM Spectrum Scale administrative command pathHigh
- targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)CVE-2020-10699 · targetcli-fb 2.1.50/2.1.51 and rtslib-fb through 2.1.72 (configuration tooling for the Linux LIO iSCSI/NVMe-oF target)High
- IBM Platform LSF / Spectrum LSF Suite (debug configuration file permissions): With specific debug settings enabled, LSFCVE-2020-4278 · IBM Platform LSF / Spectrum LSF Suite (debug configuration file permissions)High
- IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials): A user who is merely allowed to submit LSF jobsCVE-2020-4983 · IBM Spectrum LSF / LSF Suite (authentication, hard-coded credentials)High
- AMD System Management Unit (SMU) mailbox interface: A malicious user can manipulate SMU mailbox entries and reachCVE-2021-26331 · AMD System Management Unit (SMU) mailbox interfaceHigh
- Linux iSCSI: iSCSI netlink structures lack length checksCVE-2021-27365 · Linux iSCSIHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.