CVE-2016-10030
Last modified
CVE-2016-10030 is a vulnerability of currently unknown severity. The _prolog_error function in slurmd/req.c in Slurm before 15.08.13, 16.x before 16.05.7, and 17.x before 17.02.0-pre4 has a vulnerability in how the slurmd daemon informs users of a Prolog failure on a compute node. That vulnerability could allow a user to assume control of an arbitrary file on the system. EPSS estimates a 2.46% chance of exploitation in the next 30 days.
Description
The _prolog_error function in slurmd/req.c in Slurm before 15.08.13, 16.x before 16.05.7, and 17.x before 17.02.0-pre4 has a vulnerability in how the slurmd daemon informs users of a Prolog failure on a compute node. That vulnerability could allow a user to assume control of an arbitrary file on the system. Any exploitation of this is dependent on the user being able to cause or anticipate the failure (non-zero return code) of a Prolog script that their job would run on. This issue affects all Slurm versions from 0.6.0 (September 2005) to present. Workarounds to prevent exploitation of this are to either disable your Prolog script, or modify it such that it always returns 0 ("success") and adjust it to set the node as down using scontrol instead of relying on the slurmd to handle that automatically. If you do not have a Prolog set you are unaffected by this issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Schedmd | Slurm | <= 15.08.12 | — |
| Schedmd | Slurm | 16.05.0 | — |
| Schedmd | Slurm | 16.05.1 | — |
| Schedmd | Slurm | 16.05.2 | — |
| Schedmd | Slurm | 16.05.3 | — |
| Schedmd | Slurm | 16.05.4 | — |
| Schedmd | Slurm | 16.05.5 | — |
| Schedmd | Slurm | 16.05.6 | — |
| Schedmd | Slurm | 17.02.0 | Pre1 |
References
- https://github.com/SchedMD/slurm/commit/92362a92fffe60187df61f99ab11c249d44120eePatch, Vendor Advisory
- https://www.schedmd.com/news.php?id=178Mitigation, Vendor Advisory
- https://github.com/SchedMD/slurm/commit/92362a92fffe60187df61f99ab11c249d44120eePatch, Vendor Advisory
- https://www.schedmd.com/news.php?id=178Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10030?
How severe is CVE-2016-10030?
How do I fix CVE-2016-10030?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10025VMFUNC emulation in Xen 4.6.x through 4.8.x on x86 systems u…
- CVE-2016-10026ikiwiki 3.20161219 does not properly check if a revision cha…
- CVE-2016-10027Race condition in the XMPP library in Smack before 4.1.9, wh…5.9
- CVE-2016-10028The virgl_cmd_get_capset function in hw/display/virtio-gpu-3…5.5
- CVE-2016-10029The virtio_gpu_set_scanout function in QEMU (aka Quick Emula…5.5
- CVE-2016-1003Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2016-10031WampServer 3.0.6 installs two services called 'wampapache' a…
- CVE-2016-10033The mailSend function in the isMail transport in PHPMailer b…9.8
- CVE-2016-10034The setFrom function in the Sendmail adapter in the zend-mai…
- CVE-2016-10036Unrestricted file upload vulnerability in ui/artifact/upload…
- CVE-2016-10037Directory traversal in /connectors/index.php in MODX Revolut…7.3
- CVE-2016-10038Directory traversal in /connectors/index.php in MODX Revolut…
Are you affected by CVE-2016-10030?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
