Description
In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.5Attack Vector: Network
Complexity: High
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: Low
Availability: None
Affected Packages1 packages
🔴Vulnerability Details
3OSVCVE-2025-43904: In SchedMD Slurm before 24↗2026-01-16 ▶ GHSAGHSA-2778-hrgh-cpxw: In SchedMD Slurm before 24↗2026-01-16 ▶ CVEListCVE-2025-43904: In SchedMD Slurm before 24↗2026-01-16 ▶ 📋Vendor Advisories
2DebianCVE-2025-43904: slurm-wlm - In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system ca...↗2025 ▶ Microsoftdrm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing↗2024-08-13 ▶ 🕵️Threat Intelligence
1WizCVE-2025-43904 Impact, Exploitability, and Mitigation Steps | Wiz↗ ▶