GPU VulnDB

Database/Control plane, storage & DevOps

OpenPMIx (PMIx library used by Slurm and Open MPI for job launch): A race in PMIx library code that executes with UID 0

CVE-2023-41915Control plane, storage & DevOpscurated

Impact

A race in PMIx library code that executes with UID 0 lets a local attacker take ownership of arbitrary files on the node. PMIx is the wire-up layer between the scheduler and MPI ranks, so this sits directly in the multi-node launch path of every distributed training job on the cluster.

Who can reach it

A local user on a node where a PMIx-using launcher runs with root privilege - which is the normal configuration for Slurm's PMIx MPI plugin and for Open MPI's runtime.

What to do

Upgrade OpenPMIx to 4.2.6 or 5.0.1 across compute nodes and restart the launcher daemons. Note this is a separate package from Slurm - upgrading Slurm alone does not fix it, and sites frequently miss that because PMIx arrives as a distro dependency.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.