CVE-2023-41914
published 2023-11-03CVE-2023-41914: SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or…
PriorityP432high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.20%
9.6th percentile
SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | slurm-wlm | < slurm-wlm 22.05.8-4+deb12u1 (bookworm) | slurm-wlm 22.05.8-4+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| schedmd | slurm | >= 22.05 < 22.05.10 | 22.05.10 |
| schedmd | slurm | >= 23.02 < 23.02.6 | 23.02.6 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v8jm-8mp9-5962: SchedMD Slurm 23
ghsa_unreviewed·2023-11-03
CVE-2023-41914 [HIGH] CWE-362 GHSA-v8jm-8mp9-5962: SchedMD Slurm 23
SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.
OSV
CVE-2023-41914: SchedMD Slurm 23
osv·2023-11-03·CVSS 7.0
CVE-2023-41914 [HIGH] CVE-2023-41914: SchedMD Slurm 23
SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.
Debian
CVE-2023-41914: slurm-wlm - SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesyst...
vendor_debian·2023·CVSS 7.0
CVE-2023-41914 [HIGH] CVE-2023-41914: slurm-wlm - SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesyst...
SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.
Scope: local
bookworm: resolved (fixed in 22.05.8-4+deb12u1)
bullseye: open
forky: resolved (fixed in 23.02.6-1)
sid: resolved (fixed in 23.02.6-1)
trixie: resolved (fixed in 23.02.6-1)
No detection rules found.
No public exploits indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OWKTCYZT3DXEH66QXQJYB7NI7ONDRS4M/https://lists.schedmd.com/pipermail/slurm-announce/2023/000100.htmlhttps://schedmd.com/security.phphttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OWKTCYZT3DXEH66QXQJYB7NI7ONDRS4M/https://lists.schedmd.com/pipermail/slurm-announce/2023/000100.htmlhttps://schedmd.com/security.php
2023-11-03
Published