Database/Control plane, storage & DevOps

Slurm (Gentoo ebuild pkg_postinst): The Gentoo packaging runs chown across paths on the live root filesystem during
Impact
The Gentoo packaging runs chown across paths on the live root filesystem during install, so a local user who can pre-create or symlink those paths gets root-owned files planted where they choose. This is a packaging defect, not a Slurm code defect, but it lands on the controller host with root.
Who can reach it
A local user on a Gentoo host at the moment the slurm package is installed or upgraded.
What to do
Only relevant if you deploy Slurm from Gentoo ebuilds - most GPU sites do not. Update to a fixed ebuild, or install Slurm from SchedMD tarballs or distro packages you control. Verify ownership under the Slurm state and spool directories after any install.
References
Related entries
- Cisco Nexus 3000/9000 (internal file management service): Unauthenticated remote file write, read and delete as rootCVE-2021-1361 · Cisco Nexus 3000/9000 (internal file management service)Critical
- GitLab: unauthenticated SSRF through webhooks reaches the internal networkCVE-2021-22175 · GitLab (webhook request handling)Critical
- Brocade Fabric OS (hard-coded credentials): Documented hard-coded credentials in Brocade Fabric OSCVE-2021-27797 · Brocade Fabric OS (hard-coded credentials)Critical
- etcd: Authentication flaw via the debug functionCVE-2021-28235 · etcdCritical
- Siemens APOGEE PXC / MEC / MBC and TALON TC BACnet and P2 automation controllers: A cluster of critical flawsCVE-2021-31884 · Siemens APOGEE PXC / MEC / MBC and TALON TC BACnet and P2 automation controllersCritical
- Moxa NPort IAW5000A-I/O serial device server: The built-in web server doesn't validate input properly, letting a remoteCVE-2021-32974 · Moxa NPort IAW5000A-I/O serial device serverCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.