Database/Control plane, storage & DevOps

OpenPMIx (PMIx library used by Slurm and Open MPI for job launch): A race in PMIx library code that executes with UID 0
Impact
A race in PMIx library code that executes with UID 0 lets a local attacker take ownership of arbitrary files on the node. PMIx is the wire-up layer between the scheduler and MPI ranks, so this sits directly in the multi-node launch path of every distributed training job on the cluster.
Who can reach it
A local user on a node where a PMIx-using launcher runs with root privilege - which is the normal configuration for Slurm's PMIx MPI plugin and for Open MPI's runtime.
What to do
Upgrade OpenPMIx to 4.2.6 or 5.0.1 across compute nodes and restart the launcher daemons. Note this is a separate package from Slurm - upgrading Slurm alone does not fix it, and sites frequently miss that because PMIx arrives as a distro dependency.
References
Related entries
- Ceph RADOS Gateway (RGW): RGW accepts a JWT whose header declares alg "none" and never checks the signature, so anyoneCVE-2024-48916 · Ceph RADOS Gateway (RGW)High
- HPE Insight Remote Support (Java deserialization): Java deserialization letting an unauthenticated attacker executeCVE-2024-53673 · HPE Insight Remote Support (Java deserialization)High
- PostgreSQL (libpq): Improper quoting in PQescape*CVE-2025-1094 · PostgreSQL (libpq)High
- HPE Performance Cluster Manager (HPCM) GUI authentication bypass: Authentication bypass in the HPCM web GUICVE-2025-27086 · HPE Performance Cluster Manager (HPCM) GUI authentication bypassHigh
- HTCondor (IDToken authorization restrictions): The per-token authorization restrictions attached withCVE-2025-30093 · HTCondor (IDToken authorization restrictions)High
- ConnectWise ScreenConnect: ViewState code injectionCVE-2025-3935 · ConnectWise ScreenConnectHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.