Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 39: FEDORA-2023-1b25e7d001 Urgent: Pmix Concurrency Flaw

fedora
Calendar Grey October 3, 2023
Dist Fedora Esm H88
Fedora 39 has released a key security patch for PMIx that resolves vulnerabilities linked to CVE-2023-41915, enhancing protections against file exploitation
Security fix for CVE-2023-41915

Summary

The Process Management Interface (PMI) has been used for quite some time as

a means of exchanging wireup information needed for interprocess

communication. Two versions (PMI-1 and PMI-2) have been released as part of

the MPICH effort. While PMI-2 demonstrates better scaling properties than its

PMI-1 predecessor, attaining rapid launch and wireup of the roughly 1M

processes executing across 100k nodes expected for exascale operations remains

challenging.

PMI Exascale (PMIx) represents an attempt to resolve these questions by

providing an extended version of the PMI standard specifically designed to

support clusters up to and including exascale sizes. The overall objective of

the project is not to branch the existing pseudo-standard definitions - in

fact, PMIx fully supports both of the existing PMI-1 and PMI-2 APIs - but

rather to (a) augment and extend those APIs to eliminate some current

restrictions that impact scalability, and (b) provide a reference

implementation of the PMI-server that demonstrates the desired level of

scalability.

Update Information:

Security fix for CVE-2023-41915

Change Log

* Thu Sep 14 2023 Michel Lind - 4.1.3-1 - Fix CVE-2023-41915 - Update upstream source URL; pmix/pmix redirects to openpmix/openpmix - Use SPDX license identifier

References


[ 1 ] Bug #2238898 - CVE-2023-41915 pmix: race condition allows attackers to obtain ownership of arbitrary files https://bugzilla.redhat.com/show_bug.cgi?id=2238898

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1185eca900' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: pmix
Product: Fedora 39
Version: 4.1.3
Release: 1.fc39
Summary: Process Management Interface Exascale (PMIx)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here