Database/Control plane, storage & DevOps

Slurm (32-bit RPC handling): Memory corruption on 32-bit Slurm builds reachable from a crafted RPC, up to control of
Impact
Memory corruption on 32-bit Slurm builds reachable from a crafted RPC, up to control of the daemon process. SchedMD states 64-bit builds - the overwhelming majority - are not affected, so this only matters if you still run 32-bit management or login hosts.
Who can reach it
Network reach to a 32-bit Slurm daemon. No credentials described as required.
What to do
Upgrade to Slurm 17.11.13 or 18.08.5. SchedMD published fixes only for the then-supported 17.11 and 18.08 lines and states that similar flaws affect earlier 32-bit builds with no fix available, so on anything older the only resolution is upgrading. If you have 32-bit Slurm hosts left in the estate, retire them.
References
Related entries
- Optergy Proton / Enterprise building management platform: A backdoor console giving remote root code executionCVE-2019-7276 · Optergy Proton / Enterprise building management platformCritical
- Delta Controls enteliBUS Manager (eBMGR) V3.40_B-571848, dactetra service: Unauthenticated remote code executionCVE-2019-9569 · Delta Controls enteliBUS Manager (eBMGR) V3.40_B-571848, dactetra serviceCritical
- Fortinet FortiOS SSL-VPN: A logic flaw lets a user who changes their login case (e.gCVE-2020-12812 · Fortinet FortiOS SSL-VPNCritical
- Brocade Fabric OS REST API: Multiple buffer overflows in the Fabric OS REST API reachable by an unauthenticated remoteCVE-2020-15373 · Brocade Fabric OS REST APICritical
- Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management): The earlier cluster on the same consoleCVE-2020-15639 · Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management)Critical
- Slurm (Gentoo ebuild pkg_postinst): The Gentoo packaging runs chown across paths on the live root filesystem duringCVE-2020-36770 · Slurm (Gentoo ebuild pkg_postinst)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.