Hi,
The following vulnerabilities were published for slurm-wlm.
CVE-2026-65107[0]:
| Fix sbcast shared objects skipping credential verification, Fix
| possible slurmd crash on invalid sbcast filenames
CVE-2026-65108[1]:
| Fix a slurmstepd stack overflow when a job environment contains an
| oversized SPANK option variable
CVE-2026-65109[2]:
| Fix slurmstepd removing files outside the container spool directory
| when cleaning up an OCI containe, Fix slurmstepd leaving OCI container
| spool directories behind when ContainerPath contains a task id pattern
CVE-2026-65138[3]:
| Fix heap over-read when unpacking a malformed forward data RPC in
| slurmd. Fix a slurmd crash when handling a malformed forward data RPC
| with a missing socket address
CVE-2026-65139[4]:
| Fix various issues in unsafe operation/queries to the slurmdbd
CVE-2026-65140[5]:
| Fix a privilege escalation where an operator could alter Administrator
| accounts through the accounting database
CVE-2026-65165[6]:
| Fix various issues around job steps and node count discrepancies
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-65107
https://www.cve.org/CVERecord?id=CVE-2026-65107
[1] https://security-tracker.debian.org/tracker/CVE-2026-65108
https://www.cve.org/CVERecord?id=CVE-2026-65108
[2] https://security-tracker.debian.org/tracker/CVE-2026-65109
https://www.cve.org/CVERecord?id=CVE-2026-65109
[3] https://security-tracker.debian.org/tracker/CVE-2026-65138
https://www.cve.org/CVERecord?id=CVE-2026-65138
[4] https://security-tracker.debian.org/tracker/CVE-2026-65139
https://www.cve.org/CVERecord?id=CVE-2026-65139
[5] https://security-tracker.debian.org/tracker/CVE-2026-65140
https://www.cve.org/CVERecord?id=CVE-2026-65140
[6] https://security-tracker.debian.org/tracker/CVE-2026-65165
https://www.cve.org/CVERecord?id=CVE-2026-65165
[7] https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore