Debian LTS Advisory DLA-2886-1                [email protected]
https://www.debian.org/lts/security/                      Sylvain Beucler
January 17, 2022                              https://wiki.debian.org/LTS
Package        : slurm-llnl
Version        : 16.05.9-1+deb9u5
CVE ID         : CVE-2019-12838 CVE-2020-12693 CVE-2020-27745 CVE-2021-31215
Debian Bug     : 931880 961406 974721 988439

Multiple security issues were discovered in the Simple Linux Utility
for Resource Management (SLURM), a cluster resource management and job
scheduling system, which could result in denial of service,
information disclosure or privilege escalation.


    SchedMD Slurm allows SQL Injection.


    In the rare case where Message Aggregation is enabled, Slurm
    allows Authentication Bypass via an Alternate Path or Channel. A
    race condition allows a user to launch a process as an arbitrary


    RPC Buffer Overflow in the PMIx MPI plugin.


    SchedMD Slurm allows remote code execution as SlurmUser because
    use of a PrologSlurmctld or EpilogSlurmctld script leads to
    environment mishandling.

For Debian 9 stretch, these problems have been fixed in version

