CVE-2020-27746: Race Condition
Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-27746?
CVE-2020-27746 is a vulnerability in Slurm where sensitive information can be exposed to an unauthorized actor due to a race condition in a read operation on the /proc filesystem.
How does CVE-2020-27746 affect Slurm?
CVE-2020-27746 affects Slurm versions before 19.05.8 and 20.x before 20.02.6.
Which software is affected by CVE-2020-27746?
CVE-2020-27746 affects SchedMD Slurm versions before 19.05.8 and 20.x before 20.02.6, as well as Debian Debian Linux version 10.0.
What is the severity of CVE-2020-27746?
CVE-2020-27746 has a severity rating of medium, with a severity value of 3.7.
How can I fix CVE-2020-27746?
To fix CVE-2020-27746, upgrade to Slurm version 19.05.8 or 20.02.6, or apply the appropriate remedy provided by the Debian security advisory DSA-4841.