GPU VulnDB

Database/Control plane, storage & DevOps

MUNGE (SUSE/openSUSE packaging): The munge package's install scripts follow symlinks, so a local attacker who controls

CVE-2019-3691Control plane, storage & DevOpscurated

Impact

The munge package's install scripts follow symlinks, so a local attacker who controls the munge account can get root-owned files written to paths of their choosing. On a Slurm cluster the munge account is present on every node, which makes this a broad local escalation surface rather than a one-host issue.

Who can reach it

Local attacker with control of the munge user on a SUSE Linux Enterprise 15 or openSUSE host, exploited during package install or upgrade.

What to do

Apply the SUSE munge package update on all nodes. Not applicable if you build MUNGE from source or run a non-SUSE distro.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.