GPU VulnDB

Database/Control plane, storage & DevOps

Slurm (Gentoo ebuild pkg_postinst): The Gentoo packaging runs chown across paths on the live root filesystem during

CVE-2020-36770Control plane, storage & DevOpscurated

Impact

The Gentoo packaging runs chown across paths on the live root filesystem during install, so a local user who can pre-create or symlink those paths gets root-owned files planted where they choose. This is a packaging defect, not a Slurm code defect, but it lands on the controller host with root.

Who can reach it

A local user on a Gentoo host at the moment the slurm package is installed or upgraded.

What to do

Only relevant if you deploy Slurm from Gentoo ebuilds - most GPU sites do not. Update to a fixed ebuild, or install Slurm from SchedMD tarballs or distro packages you control. Verify ownership under the Slurm state and spool directories after any install.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.