GPU VulnDB

Database/NVIDIA / GPU stack

Altair Grid Engine (error message handling): Grid Engine leaks password hash material in error messages. Hashes lifted

CVE-2025-40760NVIDIA / GPU stackSSA-514895curated

Impact

Grid Engine leaks password hash material in error messages. Hashes lifted from a scheduler are directly crackable offline, and the accounts they belong to are the ones with rights over job placement.

Who can reach it

A local user able to provoke the error condition on a Grid Engine host. Affects all versions before V2026.0.0.

What to do

Upgrade Altair Grid Engine to V2026.0.0 and restart the daemons. Rotate the credentials for any account whose hash could have been exposed. Note that Altair advisories now ship through Siemens ProductCERT, not Altair's own site.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.