Skip to content
AWSGHSA-x775-rxcq-38x8

Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8

CriticalPublished May 16, 2022

AWS ParallelCluster versions **3.1.4** and **2.11.7** were released in order to update the Slurm software to versions 21.08.8 and 20.11.9, respectively. This change was made in response to SchedMD’s release of these versions on 2022-05-04, to provide fixes related to the following CVEs: CVE-2022-29500, CVE-2022-29501, and CVE-2022-29502.

GitHub advisory

Affected versions

PackageAffectedFixed in
Slurm
Product
< 20.11.920.11.9
Details and references

More AWS advisories

All AWS
Advisory
Privilege Escalation Vector in CloudWatch Agent for Windows
High7.1Dec 10, 2022
Issue with configuring session ticket names in s2n-tls
MediumSep 27, 2022
Server denial-of-service by using sslv2 message format in a HelloRetryRequest handshake
LowSep 27, 2022
Partial Path Traversal in aws-cpp-sdk-transfer
MediumAug 9, 2022
Partial Path Traversal in com.amazonaws:aws-java-sdk-s3
High7.9Jul 15, 2022
Potential denial of service when sending version negotiation or close packets
MediumMay 5, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.