GPU VulnDB

Database/Control plane, storage & DevOps

Slurm (32-bit RPC handling): Memory corruption on 32-bit Slurm builds reachable from a crafted RPC, up to control of

CVE-2019-6438Control plane, storage & DevOpscurated

Impact

Memory corruption on 32-bit Slurm builds reachable from a crafted RPC, up to control of the daemon process. SchedMD states 64-bit builds - the overwhelming majority - are not affected, so this only matters if you still run 32-bit management or login hosts.

Who can reach it

Network reach to a 32-bit Slurm daemon. No credentials described as required.

What to do

Upgrade to Slurm 17.11.13 or 18.08.5. SchedMD published fixes only for the then-supported 17.11 and 18.08 lines and states that similar flaws affect earlier 32-bit builds with no fix available, so on anything older the only resolution is upgrading. If you have 32-bit Slurm hosts left in the estate, retire them.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.