Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE 12 SP5: 2024:0316-1 Critical: Slurm Permission Update

suse
Calendar Grey February 2, 2024
Dist Suse Esm H88
The latest slurm update tackles urgent vulnerabilities related to code execution threats. Users are advised to implement the suggested patches right away.
* bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053

Summary

## This update for slurm fixes the following issues: * CVE-2023-49933: Fixed a message extension attack that could bypass the message hash (bsc#1218046). * CVE-2023-49936: Fixed a NULL pointer dereference (bsc#1218050). * CVE-2023-49937: Fixed a double free that could lead to denial of service or code execution (bsc#1218051). * CVE-2023-49938: Fixed an incorrect access control issue that could allow an attacker to modify their extended group list (bsc#1218053). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * HPC Module 12 zypper in -t patch SUSE-SLE-Module-HPC-12-2024-315=1 ## Package List: * HPC Module 12 (aarch64 x86_64)

References

* bsc#1218046

* bsc#1218050

* bsc#1218051

* bsc#1218053

Cross-

* CVE-2023-49933

* CVE-2023-49936

* CVE-2023-49937

* CVE-2023-49938

CVSS scores:

* CVE-2023-49933 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2023-49933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2023-49936 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

* CVE-2023-49936 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-49937 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

* CVE-2023-49937 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2023-49938 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2023-49938 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected Products:

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:0315-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here