GPU VulnDB

Database/Container, Kubernetes & orchestration

Slurm: Filesystem race conditions allow gaining ownership of, overwriting, or deleting files

CVE-2023-41914Container, Kubernetes & orchestrationcurated

Impact

Filesystem race conditions allow gaining ownership of, overwriting, or deleting files

Who can reach it

Any user who can submit a job

What to do

Upgrade Slurm

Fleet impact

How widespread

Very common - Slurm 22.05.x / 23.02.x branches

Cost to remediate

daemon-restart - upgrade slurmd/slurmctld on every node; running jobs survive a slurmd restart in many configs, so this is cheaper than a runc bug but still fleet-wide

Why it hits the whole fleet

TOCTOU race in Slurm file handling lets a low-privilege job take ownership of, overwrite or delete arbitrary files, escalating on any compute node the scheduler touches

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.