CVE-2022-29501: Critical severity slurm workload manager vulnerability
Published May 5, 2022
·Updated
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution.
Affected Software
12 affected componentsFixes available
debian/slurm-wlm<=20.11.7+really20.11.4-2, <=21.08.7-1
21.08.8.2-120.11.7+really20.11.4-2+deb11u1
ubuntu/slurm-llnl<19.05.5-1ubuntu0.1~
19.05.5-1ubuntu0.1~
ubuntu/slurm-llnl<21.08.8, <20.11.9
21.08.820.11.9
ubuntu/slurm-wlm<21.08.5-2ubuntu1+
21.08.5-2ubuntu1+
ubuntu/slurm-wlm<21.08.8.2-1, <21.08.8
21.08.8.2-121.08.8
debian/slurm-wlm
20.11.7+really20.11.4-2+deb11u122.05.8-4+deb12u224.05.1-2
SchedMD Slurm<20.11.9
SchedMD Slurm>=21.08.0<21.08.08
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Debian Debian Linux=11.0
Remediation
Patch Available
Event History
May 5, 2022
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·04:13 PM
Data Sourced
via MITRE·04:13 PM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:08 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-29501.
2
What is the severity level of CVE-2022-29501?
The severity level of CVE-2022-29501 is critical.
3
What is the affected software for CVE-2022-29501?
The affected software for CVE-2022-29501 is SchedMD Slurm versions 21.08.x through 20.11.x.
4
What is the impact of CVE-2022-29501?
CVE-2022-29501 can lead to the escalation of privileges and code execution.
5
How do I fix CVE-2022-29501?
To fix CVE-2022-29501, update to SchedMD Slurm version 21.08.8 or 20.11.9.