Authentication bypass using an alternate path or channel in Slurm - CVE-2020-12693
Published: September 14, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to a race condition during authentication process, if Message Aggregation is enabled. A remote non-authenticated attacker can send specially crafted request to the application, bypass authentication process and execute arbitrary code on the system.
Affected software
SUSE Linux Enterprise Module for HPC
Ubuntu
Opensuse
Fedora
slurm-llnl (Debian package)
slurmctld (Ubuntu package)
slurm-llnl-sview (Ubuntu package)
slurm-llnl-torque (Ubuntu package)
slurm-llnl-basic-plugins (Ubuntu package)
libslurm26 (Ubuntu package)
libslurmdb26 (Ubuntu package)
slurm-wlm-basic-plugins (Ubuntu package)
sview (Ubuntu package)
libslurmdb-perl (Ubuntu package)
slurm-llnl-slurmdbd (Ubuntu package)
slurmdbd (Ubuntu package)
slurm-llnl (Ubuntu package)
slurm-wlm-emulator (Ubuntu package)
libslurmdb29 (Ubuntu package)
libslurm-perl (Ubuntu package)
libslurm29 (Ubuntu package)
libpmi0 (Ubuntu package)
slurm-wlm (Ubuntu package)
slurm-client (Ubuntu package)
libpam-slurm (Ubuntu package)
slurmd (Ubuntu package)
slurm-wlm-torque (Ubuntu package)
slurm-client-emulator (Ubuntu package)
pdsh-machines-debuginfo
pdsh-netgroup
pdsh-netgroup-debuginfo
pdsh-slurm
pdsh-slurm_18_08
pdsh-slurm_18_08-debuginfo
pdsh-slurm_20_02
pdsh-slurm_20_02-debuginfo
pdsh-slurm_20_11
pdsh-slurm_20_11-debuginfo
pdsh_slurm_18_08-debugsource
pdsh_slurm_20_02-debugsource
pdsh_slurm_20_11-debugsource
pdsh-slurm-debuginfo
pdsh-genders-debuginfo
pdsh-genders
pdsh-dshgroup-debuginfo
pdsh-dshgroup
pdsh-debugsource
pdsh-debuginfo
pdsh
pdsh-machines
slurm
slurm_20_11-sql-debuginfo
slurm_20_11-node
slurm_20_11-node-debuginfo
slurm_20_11-pam_slurm
slurm_20_11-pam_slurm-debuginfo
slurm_20_11-plugins
slurm_20_11-plugins-debuginfo
slurm_20_11-slurmdbd
slurm_20_11-slurmdbd-debuginfo
slurm_20_11-sql
slurm_20_11-munge-debuginfo
slurm_20_11-sview
slurm_20_11-sview-debuginfo
slurm_20_11-torque
slurm_20_11-torque-debuginfo
slurm_20_11-webdoc
libslurm36-debuginfo
slurm_20_11-config
libpmi0_20_11-debuginfo
libpmi0_20_11
libnss_slurm2_20_11-debuginfo
libnss_slurm2_20_11
perl-slurm_20_11
perl-slurm_20_11-debuginfo
slurm_20_11
slurm_20_11-auth-none
slurm_20_11-auth-none-debuginfo
libslurm36
slurm_20_11-config-man
slurm_20_11-debuginfo
slurm_20_11-debugsource
slurm_20_11-devel
slurm_20_11-doc
slurm_20_11-lua
slurm_20_11-lua-debuginfo
slurm_20_11-munge
How to mitigate CVE-2020-12693
slurm-llnl (Debian package) - update to 18.08.5.2-1+deb10u2
slurmctld (Ubuntu package) - update to Ubuntu Pro
slurm-llnl-sview (Ubuntu package) - update to Ubuntu Pro
slurm-llnl-torque (Ubuntu package) - update to Ubuntu Pro
slurm-llnl-basic-plugins (Ubuntu package) - update to Ubuntu Pro
libslurm26 (Ubuntu package) - update to Ubuntu Pro
libslurmdb26 (Ubuntu package) - update to Ubuntu Pro
slurm-wlm-basic-plugins (Ubuntu package) - update to Ubuntu Pro
sview (Ubuntu package) - update to Ubuntu Pro
libslurmdb-perl (Ubuntu package) - update to Ubuntu Pro
slurm-llnl-slurmdbd (Ubuntu package) - update to Ubuntu Pro
slurmdbd (Ubuntu package) - update to Ubuntu Pro
slurm-llnl (Ubuntu package) - update to Ubuntu Pro
slurm-wlm-emulator (Ubuntu package) - update to Ubuntu Pro
libslurmdb29 (Ubuntu package) - update to Ubuntu Pro
libslurm-perl (Ubuntu package) - update to Ubuntu Pro
libslurm29 (Ubuntu package) - update to Ubuntu Pro
libpmi0 (Ubuntu package) - update to Ubuntu Pro
slurm-wlm (Ubuntu package) - update to Ubuntu Pro
slurm-client (Ubuntu package) - update to Ubuntu Pro
libpam-slurm (Ubuntu package) - update to Ubuntu Pro
slurmd (Ubuntu package) - update to Ubuntu Pro
slurm-wlm-torque (Ubuntu package) - update to Ubuntu Pro
slurm-client-emulator (Ubuntu package) - update to Ubuntu Pro
pdsh-machines-debuginfo - update to 2.34-7.32.1
pdsh-netgroup - update to 2.34-7.32.1
pdsh-netgroup-debuginfo - update to 2.34-7.32.1
pdsh-slurm - update to 2.34-7.32.1
pdsh-slurm_18_08 - update to 2.34-7.32.1
pdsh-slurm_18_08-debuginfo - update to 2.34-7.32.1
pdsh-slurm_20_02 - update to 2.34-7.32.1
pdsh-slurm_20_02-debuginfo - update to 2.34-7.32.1
pdsh-slurm_20_11 - update to 2.34-7.32.1
pdsh-slurm_20_11-debuginfo - update to 2.34-7.32.1
pdsh_slurm_18_08-debugsource - update to 2.34-7.32.1
pdsh_slurm_20_02-debugsource - update to 2.34-7.32.1
pdsh_slurm_20_11-debugsource - update to 2.34-7.32.1
pdsh-slurm-debuginfo - update to 2.34-7.32.1
pdsh-genders-debuginfo - update to 2.34-7.32.1
pdsh-genders - update to 2.34-7.32.1
pdsh-dshgroup-debuginfo - update to 2.34-7.32.1
pdsh-dshgroup - update to 2.34-7.32.1
pdsh-debugsource - update to 2.34-7.32.1
pdsh-debuginfo - update to 2.34-7.32.1
pdsh - update to 2.34-7.32.1
pdsh-machines - update to 2.34-7.32.1
slurm - addressed in versions 19.05.7-1.fc30, 19.05.7-1.fc31, 19.05.7-1.fc32
slurm_20_11-sql-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-node - update to 20.11.4-3.5.1
slurm_20_11-node-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-pam_slurm - update to 20.11.4-3.5.1
slurm_20_11-pam_slurm-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-plugins - update to 20.11.4-3.5.1
slurm_20_11-plugins-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-slurmdbd - update to 20.11.4-3.5.1
slurm_20_11-slurmdbd-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-sql - update to 20.11.4-3.5.1
slurm_20_11-munge-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-sview - update to 20.11.4-3.5.1
slurm_20_11-sview-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-torque - update to 20.11.4-3.5.1
slurm_20_11-torque-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-webdoc - update to 20.11.4-3.5.1
libslurm36-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-config - update to 20.11.4-3.5.1
libpmi0_20_11-debuginfo - update to 20.11.4-3.5.1
libpmi0_20_11 - update to 20.11.4-3.5.1
libnss_slurm2_20_11-debuginfo - update to 20.11.4-3.5.1
libnss_slurm2_20_11 - update to 20.11.4-3.5.1
perl-slurm_20_11 - update to 20.11.4-3.5.1
perl-slurm_20_11-debuginfo - update to 20.11.4-3.5.1
slurm_20_11 - update to 20.11.4-3.5.1
slurm_20_11-auth-none - update to 20.11.4-3.5.1
slurm_20_11-auth-none-debuginfo - update to 20.11.4-3.5.1
libslurm36 - update to 20.11.4-3.5.1
slurm_20_11-config-man - update to 20.11.4-3.5.1
slurm_20_11-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-debugsource - update to 20.11.4-3.5.1
slurm_20_11-devel - update to 20.11.4-3.5.1
slurm_20_11-doc - update to 20.11.4-3.5.1
slurm_20_11-lua - update to 20.11.4-3.5.1
slurm_20_11-lua-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-munge - update to 20.11.4-3.5.1
External References
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00035.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KNL5E5SK4WP6M3DKU4IKW2NPQD2XTZ4Y/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3RGQB3EWDLOLTSPAJPPWZEPQK3O3AUH/
- https://lists.schedmd.com/pipermail/slurm-announce/2020/000036.html
- https://www.schedmd.com/news.php?id=236