CVE-2025-43904
published 2026-01-16CVE-2025-43904: In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.
PriorityP422medium4.2CVSS 3.1
AVNACHPRLUINSUCLILAN
EPSS
0.24%
15.6th percentile
In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | slurm-wlm | < slurm-wlm 22.05.8-4+deb12u3 (bookworm) | slurm-wlm 22.05.8-4+deb12u3 (bookworm) |
| msrc | azl3_kernel_6.6.64.2-9_on_azure_linux_3.0 | — | — |
| msrc | azl3_kernel_6.6.92.2-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0 | — | — |
| schedmd | slurm | < 23.11.11 | 23.11.11 |
| schedmd | slurm | >= 24 < 24.05.8 | 24.05.8 |
| schedmd | slurm | >= 24.06 < 24.11.5 | 24.11.5 |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
osv4.2MEDIUM
vendor_msrc5.5MEDIUM
vendor_debian4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-43904: slurm-wlm - In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system ca...
vendor_debian·2025·CVSS 4.2
CVE-2025-43904 [MEDIUM] CVE-2025-43904: slurm-wlm - In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system ca...
In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.
Scope: local
bookworm: resolved (fixed in 22.05.8-4+deb12u3)
bullseye: open
forky: resolved (fixed in 24.11.5-1)
sid: resolved (fixed in 24.11.5-1)
trixie: resolved (fixed in 24.11.5-1)
Microsoft
drm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing
vendor_msrc·2024-08-13·CVSS 5.5
CVE-2024-43904 [MEDIUM] CWE-476 drm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing
drm/amd/display: Add null checks for 'stream' and 'plane' before dereferencing
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
R
OSV
CVE-2025-43904: In SchedMD Slurm before 24
osv·2026-01-16·CVSS 4.2
CVE-2025-43904 [MEDIUM] CVE-2025-43904: In SchedMD Slurm before 24
In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.
GHSA
GHSA-2778-hrgh-cpxw: In SchedMD Slurm before 24
ghsa_unreviewed·2026-01-16
CVE-2025-43904 [MEDIUM] CWE-863 GHSA-2778-hrgh-cpxw: In SchedMD Slurm before 24
In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-43904 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.2
CVE-2025-43904 [MEDIUM] CVE-2025-43904 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-43904 :
Linux Debian vulnerability analysis and mitigation
In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.
Source : NVD
## 4.2
Score
Published January 16, 2026
Severity MEDIUM
CNA Score 4.2
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
slurm_22_05-auth-none
slurm_22_05-node
Sources
NVD
Debian 11 Severity MEDIUM No Fix Added at: Jul 08, 2025
Debian 12, 13 Severity MEDIUM Has Fix Added at: Jul 08, 2025
Debian 14 Severity MEDIUM Has Fix Added at: Aug 10, 2025
Bugzilla
CVE-2025-43904 slurm: accounting system can allow a coordinator to promote a user to administrator [fedora-42]
bugzilla·2026-01-16·CVSS 4.2
CVE-2025-43904 [MEDIUM] CVE-2025-43904 slurm: accounting system can allow a coordinator to promote a user to administrator [fedora-42]
CVE-2025-43904 slurm: accounting system can allow a coordinator to promote a user to administrator [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently mainta
2026-01-16
Published