SB2017110114 - Fedora 27 update for slurm



SB2017110114 - Fedora 27 update for slurm

Published: November 1, 2017 Updated: April 24, 2025

Security Bulletin ID SB2017110114
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Untrusted search path (CVE-ID: CVE-2017-15566)

The vulnerability allows a local authenticated user to execute arbitrary code.

Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.


Remediation

Install update from vendor's website.