Bug 1216207 (CVE-2023-41914) - VUL-0: CVE-2023-41914: slurm,slurm_18_08,slurm_20_02,slurm_20_11,slurm_22_05,slurm_23_02,slurmlibs: race conditions causing file overwrites
Summary: VUL-0: CVE-2023-41914: slurm,slurm_18_08,slurm_20_02,slurm_20_11,slurm_22_05,...
Status: RESOLVED FIXED
Alias: CVE-2023-41914
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/381782/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-41914:8.8:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-10-13 08:34 UTC by SMASH SMASH
Modified: 2024-06-07 15:02 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-10-13 08:34:25 UTC
References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-41914

https://groups.google.com/g/slurm-users/c/N9WHFVefSHA

Slurm versions 23.02.6 and 22.05.10 are now available to address a
number of filesystem race conditions that could let an attacker take
control of an arbitrary file, or remove entire directories' contents
(CVE-2023-41914).

SchedMD customers were informed on September 27th and provided a patch
on request; this process is documented in our security policy [1].

--------
CVE-2023-41914:

A number of race conditions have been identified within the
slurmd/slurmstepd processes that can lead to the user taking ownership
of an arbitrary file on the system. A related issue can lead to the user
overwriting an arbitrary file on the compute node (although with data
that is not directly under their control). A related issue can also lead
to the user deleting all files and sub-directories of an arbitrary
target directory on the compute node.

Thank you to François Diakhate (CEA) for reporting the original issue to
us. A number of related issues were found during an extensive audit of
Slurm's filesystem handling code in reaction to that report, and are
included here in this same disclosure.
--------

SchedMD only issues security fixes for the supported releases (currently
23.02 and 22.05). Due to the complexity of these fixes, we do not
recommend attempting to backport the fixes to older releases, and
strongly encourage sites to upgrade to fixed versions immediately.

Downloads are available at https://www.schedmd.com/downloads.php .
Comment 1 Egbert Eich 2023-10-13 13:00:06 UTC
Submissions predated this ticket:
Slurm v23.03:
310340: SUSE:SLE-15-SP5:Update

310341 SUSE:SLE-12-SP2:GA:Products:Update
310342 SUSE:SLE-15-SP1:Update
310343 SUSE:SLE-15-SP3:Update
310344 SUSE:SLE-15-SP3:Update

Slurm v22.05:
310348: SUSE:SLE-12-SP2:GA:Products:Update
310349: SUSE:SLE-15-SP1:Update
310350: SUSE:SLE-15-SP2:Update
310351: SUSE:SLE-15-SP3:Update
Comment 6 Egbert Eich 2023-10-17 06:51:59 UTC
Submissions:
Slurm v20.11:
310525 SUSE:SLE-15-SP3:Update
310526 SUSE:SLE-12-SP2:GA:Products:Update
310527 SUSE:SLE-15-SP1:Update
310528 SUSE:SLE-15-SP2:Update

Slurm v20.02:
310613 SUSE:SLE-15-SP2:Update
310614 SUSE:SLE-12-SP2:GA:Products:Update
310615 SUSE:SLE-15-SP1:Update

Slurm v18.08:
310638 SUSE:SLE-15-SP1:Update
310639 SUSE:SLE-12-SP2:GA:Products:Update

Slurm v17.02:
310640 SUSE:SLE-12-SP2:GA:Products:Update
Comment 8 OBSbugzilla Bot 2023-10-17 08:45:02 UTC
This is an autogenerated message for OBS integration:
This bug (1216207) was mentioned in
https://build.opensuse.org/request/show/1118220 Factory / slurm
Comment 9 Maintenance Automation 2023-10-18 12:30:01 UTC
SUSE-SU-2023:4114-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1208810, 1216207
CVE References: CVE-2023-41914
Sources used:
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (src): slurm-20.11.9-150300.4.9.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): slurm-20.11.9-150300.4.9.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Maintenance Automation 2023-10-18 12:30:03 UTC
SUSE-SU-2023:4113-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1208810, 1216207
CVE References: CVE-2023-41914
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (src): slurm_20_11-20.11.9-150100.3.19.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Maintenance Automation 2023-10-18 16:30:05 UTC
SUSE-SU-2023:4121-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1208810, 1216207
CVE References: CVE-2023-41914
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (src): slurm-18.08.9-150100.3.25.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Maintenance Automation 2023-10-18 16:30:07 UTC
SUSE-SU-2023:4120-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1208810, 1216207
CVE References: CVE-2023-41914
Sources used:
HPC Module 12 (src): slurm-17.02.11-6.56.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Maintenance Automation 2023-10-18 16:30:09 UTC
SUSE-SU-2023:4119-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1208810, 1216207
CVE References: CVE-2023-41914
Sources used:
HPC Module 12 (src): slurm_20_02-20.02.7-3.17.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 14 Maintenance Automation 2023-10-18 16:30:11 UTC
SUSE-SU-2023:4118-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1208810, 1216207
CVE References: CVE-2023-41914
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (src): slurm_20_02-20.02.7-150100.3.27.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 15 Maintenance Automation 2023-10-18 16:30:14 UTC
SUSE-SU-2023:4117-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1208810, 1216207
CVE References: CVE-2023-41914
Sources used:
HPC Module 12 (src): slurm_18_08-18.08.9-3.20.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 16 Maintenance Automation 2023-10-18 16:30:16 UTC
SUSE-SU-2023:4116-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1208810, 1216207
CVE References: CVE-2023-41914
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): slurm-20.02.7-150200.3.17.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Maintenance Automation 2023-10-18 16:30:18 UTC
SUSE-SU-2023:4115-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1208810, 1216207
CVE References: CVE-2023-41914
Sources used:
HPC Module 12 (src): slurm_20_11-20.11.9-3.16.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 18 Maintenance Automation 2023-11-01 08:30:09 UTC
SUSE-SU-2023:4329-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1208810, 1216207
CVE References: CVE-2023-41914
Sources used:
openSUSE Leap 15.4 (src): slurm_20_11-20.11.9-150200.6.13.1
openSUSE Leap 15.5 (src): slurm_20_11-20.11.9-150200.6.13.1
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): slurm_20_11-20.11.9-150200.6.13.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 21 Maintenance Automation 2023-11-24 20:30:05 UTC
SUSE-SU-2023:4566-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1216207, 1216869
CVE References: CVE-2023-41914
Sources used:
openSUSE Leap 15.3 (src): slurm_23_02-23.02.6-150300.7.14.1
openSUSE Leap 15.4 (src): slurm_23_02-23.02.6-150300.7.14.1
HPC Module 15-SP4 (src): slurm_23_02-23.02.6-150300.7.14.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (src): slurm_23_02-23.02.6-150300.7.14.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): slurm_23_02-23.02.6-150300.7.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 22 Maintenance Automation 2023-11-24 20:30:09 UTC
SUSE-SU-2023:4565-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1216207, 1216869
CVE References: CVE-2023-41914
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): slurm_23_02-23.02.6-150200.5.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 23 Maintenance Automation 2023-11-24 20:30:11 UTC
SUSE-SU-2023:4564-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1216207, 1216869
CVE References: CVE-2023-41914
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (src): slurm_23_02-23.02.6-150100.3.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 24 Maintenance Automation 2023-11-24 20:30:13 UTC
SUSE-SU-2023:4563-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1216207, 1216869
CVE References: CVE-2023-41914
Sources used:
HPC Module 12 (src): slurm_23_02-23.02.6-3.13.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 25 Maintenance Automation 2023-11-27 12:30:13 UTC
SUSE-SU-2023:4582-1: An update that solves one vulnerability and has two security fixes can now be installed.

Category: security (important)
Bug References: 1208810, 1216207, 1216869
CVE References: CVE-2023-41914
Sources used:
HPC Module 12 (src): slurm_22_05-22.05.10-3.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 26 Maintenance Automation 2023-11-27 12:30:16 UTC
SUSE-SU-2023:4581-1: An update that solves one vulnerability and has two security fixes can now be installed.

Category: security (important)
Bug References: 1208810, 1216207, 1216869
CVE References: CVE-2023-41914
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (src): slurm_22_05-22.05.10-150100.3.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 27 Maintenance Automation 2023-11-27 12:30:19 UTC
SUSE-SU-2023:4580-1: An update that solves one vulnerability and has two security fixes can now be installed.

Category: security (important)
Bug References: 1208810, 1216207, 1216869
CVE References: CVE-2023-41914
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): slurm_22_05-22.05.10-150200.5.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 28 Maintenance Automation 2023-11-27 12:30:23 UTC
SUSE-SU-2023:4579-1: An update that solves one vulnerability and has two security fixes can now be installed.

Category: security (important)
Bug References: 1208810, 1216207, 1216869
CVE References: CVE-2023-41914
Sources used:
openSUSE Leap 15.3 (src): slurm_22_05-22.05.10-150300.7.6.1
openSUSE Leap 15.4 (src): slurm_22_05-22.05.10-150300.7.6.1
openSUSE Leap 15.5 (src): slurm_22_05-22.05.10-150300.7.6.1
HPC Module 15-SP4 (src): slurm_22_05-22.05.10-150300.7.6.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (src): slurm_22_05-22.05.10-150300.7.6.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): slurm_22_05-22.05.10-150300.7.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 29 Maintenance Automation 2023-11-27 12:30:28 UTC
SUSE-SU-2023:4578-1: An update that solves one vulnerability and has one security fix can now be installed.

Category: security (important)
Bug References: 1216207, 1216869
CVE References: CVE-2023-41914
Sources used:
SUSE Package Hub 15 15-SP5 (src): slurm-23.02.6-150500.5.12.1
openSUSE Leap 15.5 (src): slurm-23.02.6-150500.5.12.1
HPC Module 15-SP5 (src): slurm-23.02.6-150500.5.12.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 30 Egbert Eich 2024-01-02 14:05:31 UTC
Ca n you check why https://smelt.suse.de/incident/31080/ has not been released for SLE-15-SP4?

While this package appeared in SLE-15-SP3 SLE-15-SP4 still contains the same code stream.
Comment 31 Marcus Meissner 2024-01-03 15:41:26 UTC
slurm is forked into the SP4 codestream:

SUSE:SLE-15-SP4:Update/slurm

we will also need a submit there.
Comment 33 Maintenance Automation 2024-01-31 08:30:04 UTC
SUSE-SU-2024:0279-1: An update that solves five vulnerabilities and has two security fixes can now be installed.

Category: security (important)
Bug References: 1216207, 1216869, 1217711, 1218046, 1218050, 1218051, 1218053
CVE References: CVE-2023-41914, CVE-2023-49933, CVE-2023-49936, CVE-2023-49937, CVE-2023-49938
Sources used:
openSUSE Leap 15.3 (src): slurm-20.11.9-150300.4.12.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): slurm-20.11.9-150300.4.12.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 34 Maintenance Automation 2024-01-31 12:30:10 UTC
SUSE-SU-2024:0288-1: An update that solves five vulnerabilities and has two security fixes can now be installed.

Category: security (important)
Bug References: 1216207, 1216869, 1217711, 1218046, 1218050, 1218051, 1218053
CVE References: CVE-2023-41914, CVE-2023-49933, CVE-2023-49936, CVE-2023-49937, CVE-2023-49938
Sources used:
openSUSE Leap 15.5 (src): slurm_20_11-20.11.9-150200.6.16.1
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): slurm_20_11-20.11.9-150200.6.16.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 35 Maintenance Automation 2024-02-02 08:30:03 UTC
SUSE-SU-2024:0313-1: An update that solves five vulnerabilities and has one security fix can now be installed.

Category: security (important)
Bug References: 1216207, 1216869, 1218046, 1218050, 1218051, 1218053
CVE References: CVE-2023-41914, CVE-2023-49933, CVE-2023-49936, CVE-2023-49937, CVE-2023-49938
Sources used:
HPC Module 12 (src): slurm_18_08-18.08.9-3.23.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 36 Maintenance Automation 2024-02-02 12:30:17 UTC
SUSE-SU-2024:0314-1: An update that solves five vulnerabilities and has three security fixes can now be installed.

Category: security (important)
Bug References: 1208810, 1216207, 1216869, 1217711, 1218046, 1218050, 1218051, 1218053
CVE References: CVE-2023-41914, CVE-2023-49933, CVE-2023-49936, CVE-2023-49937, CVE-2023-49938
Sources used:
openSUSE Leap 15.4 (src): slurm-20.11.9-150400.3.3.1
SUSE Package Hub 15 15-SP5 (src): slurm-20.11.9-150400.3.3.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src): slurm-20.11.9-150400.3.3.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src): slurm-20.11.9-150400.3.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 37 Robert Frohl 2024-06-07 15:02:46 UTC
done, closing