Database/Control plane, storage & DevOps

Slurm (NULL pointer dereference in RPC handling): A crafted message crashes the Slurm daemon. On slurmctld that stalls
Impact
A crafted message crashes the Slurm daemon. On slurmctld that stalls every scheduling decision on the cluster - no new job starts, no allocations, and GPUs sit idle until the controller is back. This is the sixth of the December 2023 batch and is the only one of that batch not already in the database.
Who can reach it
Network reach to a Slurm daemon. Same exposure surface as the rest of the 2023-12 batch, so anything that can send RPCs to slurmctld or slurmd.
What to do
Upgrade to Slurm 22.05.11, 23.02.7 or 23.11.1 and restart the daemons. slurmctld restarts preserve running jobs, so this is a low-drama upgrade - do it in the same window as the rest of the 2023-12 fixes if you have not already.
References
Related entries
- HPE OneView (clusterService authentication bypass to DoS): Authentication bypass against the OneView cluster serviceCVE-2023-50275 · HPE OneView (clusterService authentication bypass to DoS)High
- CyberPower PowerPanel Business 4.11.0 - Service Watchdog on TCP/2003: An unauthenticated attacker can repeatedlyCVE-2024-11322 · CyberPower PowerPanel Business 4.11.0 - Service Watchdog on TCP/2003High
- OpenVPN: The interactive service pipe is reachable remotelyCVE-2024-24974 · OpenVPNHigh
- Intel Neural Compressor: Unauthenticated input-validation failure leading to escalation of privilege in NeuralCVE-2024-28028 · Intel Neural CompressorHigh
- Brocade SANnav OVA appliance image, before v2.3.1 and v2.3.0a: Three defects that together mean every SANnav OVACVE-2024-29966 · Brocade SANnav OVA appliance image, before v2.3.1 and v2.3.0aHigh
- AMD - DIMM SPD address aliasing bypassing SMM isolation (AMD-SB-3014): The BadRAM SPD-aliasing technique aimed atCVE-2024-36354 · AMD - DIMM SPD address aliasing bypassing SMM isolation (AMD-SB-3014)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.