#1146563 slurm-wlm: CVE-2026-65107 CVE-2026-65108 CVE-2026-65109 CVE-2026-65138 CVE-2026-65139 CVE-2026-65140 CVE-2026-65165 #1146563
- Package:
- src:slurm-wlm
- Source:
- src:slurm-wlm
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-12 09:33:04 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for slurm-wlm. CVE-2026-65107[0]: | Fix sbcast shared objects skipping credential verification, Fix | possible slurmd crash on invalid sbcast filenames CVE-2026-65108[1]: | Fix a slurmstepd stack overflow when a job environment contains an | oversized SPANK option variable CVE-2026-65109[2]: | Fix slurmstepd removing files outside the container spool directory | when cleaning up an OCI containe, Fix slurmstepd leaving OCI container | spool directories behind when ContainerPath contains a task id pattern CVE-2026-65138[3]: | Fix heap over-read when unpacking a malformed forward data RPC in | slurmd. Fix a slurmd crash when handling a malformed forward data RPC | with a missing socket address CVE-2026-65139[4]: | Fix various issues in unsafe operation/queries to the slurmdbd CVE-2026-65140[5]: | Fix a privilege escalation where an operator could alter Administrator | accounts through the accounting database CVE-2026-65165[6]: | Fix various issues around job steps and node count discrepancies If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-65107 https://www.cve.org/CVERecord?id=CVE-2026-65107 [1] https://security-tracker.debian.org/tracker/CVE-2026-65108 https://www.cve.org/CVERecord?id=CVE-2026-65108 [2] https://security-tracker.debian.org/tracker/CVE-2026-65109 https://www.cve.org/CVERecord?id=CVE-2026-65109 [3] https://security-tracker.debian.org/tracker/CVE-2026-65138 https://www.cve.org/CVERecord?id=CVE-2026-65138 [4] https://security-tracker.debian.org/tracker/CVE-2026-65139 https://www.cve.org/CVERecord?id=CVE-2026-65139 [5] https://security-tracker.debian.org/tracker/CVE-2026-65140 https://www.cve.org/CVERecord?id=CVE-2026-65140 [6] https://security-tracker.debian.org/tracker/CVE-2026-65165 https://www.cve.org/CVERecord?id=CVE-2026-65165 [7] https://github.com/SchedMD/slurm/blob/slurm-26.05/CHANGELOG/slurm-26.05.md#changes-in-26054 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
slurm-wlm, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1146563@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Gennaro Oliva <oliva@debian.org> (supplier of updated slurm-wlm package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 03 Sep 2026 14:42:16 +0200
Source: slurm-wlm
Architecture: source
Version: 26.05.4-1
Distribution: unstable
Urgency: high
Maintainer: Debian HPC Team <debian-hpc@lists.debian.org>
Changed-By: Gennaro Oliva <oliva@debian.org>
Closes: 1146563
Changes:
slurm-wlm (26.05.4-1) unstable; urgency=high
.
* New upstream release (Closes: #1146563)
* Fix security vulnerabilities:
- CVE-2026-65107
- CVE-2026-65108
- CVE-2026-65109
- CVE-2026-65138
- CVE-2026-65139
- CVE-2026-65140
- CVE-2026-65165
Checksums-Sha1:
48bcd1204ea2afa58e9917337a807716fdf4924f 5415 slurm-wlm_26.05.4-1.dsc
fcd8af51000b75ecb680d266b40aa94113b6d7f1 9608686 slurm-wlm_26.05.4.orig.tar.gz
21e9c7c848cbda7026e904ab258cb5ff11b06189 140280 slurm-wlm_26.05.4-1.debian.tar.xz
66f341fb8df56635b4e2d28d2415ae24b0d67c25 30891 slurm-wlm_26.05.4-1_amd64.buildinfo
Checksums-Sha256:
59a55eb741dbfe9d31a8889c4ad1b1740f09dd716af7a6bfbef82e3938443ff3 5415 slurm-wlm_26.05.4-1.dsc
0e522d39324b7b7da5e8096c678c4af00500ca4c3fe2e6da7e4f8d01f7082ec7 9608686 slurm-wlm_26.05.4.orig.tar.gz
79b54ec4bf9185246b88325ec53b6b5558e1c6b21d2f2ea013ef9aad6d374940 140280 slurm-wlm_26.05.4-1.debian.tar.xz
11aee74f76de4b8d6dfc2595bc6fa8c5ff3c06fe28d8e1755580c94578ebf2f3 30891 slurm-wlm_26.05.4-1_amd64.buildinfo
Files:
96bd8bdecf6e38ea7f79e2e6f9a4c364 5415 admin optional slurm-wlm_26.05.4-1.dsc
394db6a8e0516597275aa09d4bcd9ba6 9608686 admin optional slurm-wlm_26.05.4.orig.tar.gz
9bb8a2b03a8b0fb57a4ff071a2c38d35 140280 admin optional slurm-wlm_26.05.4-1.debian.tar.xz
dc2936d5b38db204d7506915a1f73b9e 30891 admin optional slurm-wlm_26.05.4-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJFBAEBCgAvFiEE6zNF9WRBuLgad5h2ffpBrZYZhdcFAmqdzvoRHG9saXZhQGRl
Ymlhbi5vcmcACgkQffpBrZYZhde4fQ/7BLZsZSVYHZmWrMts6+Nzirw/paYHj4if
TI6cwIMTGipXQ0nq3Rz51I0NPvXFPcxmJiG9lUMmw6tQlKfmPBafBJbjlsCc85EA
1KI3VhCkMwY4LP8bgqSIsE6ldTkB8ib8uHovayeIPPND80sAVuKCkaJYUUoGffjF
hEu/IY1Z+7M4AJmU5turip2rBemHVaApWttz1GpKoiYWlDMHuYJgcw0wNoDxJJpQ
zP8MA8uOmOXo0t/WfoYKFyxd9DSEj0aU+CQUqav6YdyNlOjkaY1l2atFIrAgdoEQ
h8x9jbjDCMm/+1aWEylwnk05MR5A2pNm/2mTxKEcSzVZJMtHkXjWcqMdymDn0Elw
BSxx4COOvq5wf9X6bn/0jY+odL/xP0jT4nb+Cyf8+O7D47Y04ZQL9X7aVFxGh70l
YQDKYNnLlkQwCGPm9yEtP7d8EKZtdRIDipvIVPwkvb/p2ZZqnafDH2h+OOXvlf82
mJ94vVNvNIY2TBQNfEqkpYcjFe54Shhw3NCll+q6eWXkusjUKAJ2Z2YAxPQJPMte
dWUpEb5BgWLT97ZDTf9LpURiHrqsb+j6r97cymMefBT9D2Gt/5leGVKmN1Pm+0Vn
V2GTwkZce2nPWlYalU3R5y379g5nwNq4RXd4nte7y5pMQPLKUMdHGYtrGyNErBMt
jey3oa8e6dM=
=Wyq9
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
slurm-wlm, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1146563@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Aron Xu <aron@debian.org> (supplier of updated slurm-wlm package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 07 Sep 2026 15:28:59 +0800
Source: slurm-wlm
Architecture: source
Version: 24.11.5-4+deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian HPC Team <debian-hpc@lists.debian.org>
Changed-By: Aron Xu <aron@debian.org>
Closes: 1146563
Changes:
slurm-wlm (24.11.5-4+deb13u1) trixie-security; urgency=high
.
* Non-maintainer upload.
* Fix multiple security issues by backporting the upstream fixes from the
slurm-25.05 branch (Closes: #1146563):
* CVE-2026-65107: sbcast shared objects skipped credential verification,
and slurmd could crash on invalid sbcast filenames.
* CVE-2026-65108: slurmstepd stack overflow when a job environment
contains an oversized SPANK option variable.
* CVE-2026-65109: slurmstepd could remove files outside the container
spool directory when cleaning up an OCI container, and left spool
directories behind when ContainerPath contains a task id pattern.
* CVE-2026-65138: heap over-read and NULL pointer dereference in slurmd
when unpacking a malformed forward data RPC.
* CVE-2026-65139: slurmdbd used unsafe cluster names and non-numeric id
lists in accounting database queries.
* CVE-2026-65140: privilege escalation where an operator could alter
Administrator accounts through the accounting database.
* CVE-2026-65165: a job step using arbitrary distribution could end up
with a node count disagreeing with its node list. The count is now taken
from the list, hostlist functions are rejected in it, and a list that
disagrees with the requested node count is refused.
* Fix possible slurmstepd crash on step socket requests with invalid
lengths.
Checksums-Sha1:
d8ae679f27861ab149aac3eb3721d1a1b099d594 5075 slurm-wlm_24.11.5-4+deb13u1.dsc
ee73999cd33002a5275ceb56c90874abc281a327 9907599 slurm-wlm_24.11.5.orig.tar.gz
eb8e11dc438e7b18260666a1ccbbc30acd3ca7ae 154864 slurm-wlm_24.11.5-4+deb13u1.debian.tar.xz
47a49950b8ef7e88e85145138bff18cf31a7aebe 6563 slurm-wlm_24.11.5-4+deb13u1_source.buildinfo
Checksums-Sha256:
3cba9330f0f2d4189540558aba7f6ebb0d97f26fb5d8c1b4e90f1de7df1d9153 5075 slurm-wlm_24.11.5-4+deb13u1.dsc
e1a5547edd212c38b5e3230a284133f777b32746551f094aaa81cc4af375e332 9907599 slurm-wlm_24.11.5.orig.tar.gz
978126ae878e975b81d1eb147eb4dd622431e05edd1a9ae45743d1f8e1790c14 154864 slurm-wlm_24.11.5-4+deb13u1.debian.tar.xz
b47d2fdeb434e05e1b6fa767e5b6e5fd48d0c1a7860c14badea38ed68521c518 6563 slurm-wlm_24.11.5-4+deb13u1_source.buildinfo
Files:
365fffdd2e775b394ef830120bf042aa 5075 admin optional slurm-wlm_24.11.5-4+deb13u1.dsc
4059b2f58afe4b9494be08b1f1195e4c 9907599 admin optional slurm-wlm_24.11.5.orig.tar.gz
83f512126cd75073413bf75694ffc059 154864 admin optional slurm-wlm_24.11.5-4+deb13u1.debian.tar.xz
811806ebccede14d338f093cba371285 6563 admin optional slurm-wlm_24.11.5-4+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCgAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmqfuvEACgkQ+GQ1dHE8
m67L0Qf9G2/7ImaEo4MkfgKL49/fGiovM2ubpvUHx7EhpxjXgopUWM5QCe69eLEO
hYoH7ZLZ1RD+01MdQKqyI4EuLTMGPw7Fv1zISzVdl6x8yBPoPj6NOUrZTZWicU55
Bb3TF4dPSb/zzoXo6hcES2+6SGJqmgWUS72TrjS4HqVeKPeGqJaXyuynsx2p6KR8
nkB+PJgbEBI86l2FUqYffZvYlEOj6dlSiy8O+PaFCAJmUguaEfHKAaWQ4nJX6a9P
S5VeyHI/pO3yxEye4k9OtqtihZv0LCEJgaJ0xVi/qFIoANf0H/c9N1U1Zjt5A2gO
NXSfQ7HOyRS433jzat4OBOk4lL13nQ==
=Hjbk
-----END PGP SIGNATURE-----