{"affected":[{"ecosystem_specific":{"binaries":[{"libpmi0":"17.02.9-6.10.1","libslurm29":"16.05.8.1-6.1","libslurm31":"17.02.9-6.10.1","pdsh":"2.33-7.5.17","perl-slurm":"17.02.9-6.10.1","slurm":"17.02.9-6.10.1","slurm-auth-none":"17.02.9-6.10.1","slurm-devel":"17.02.9-6.10.1","slurm-doc":"17.02.9-6.10.1","slurm-lua":"17.02.9-6.10.1","slurm-munge":"17.02.9-6.10.1","slurm-pam_slurm":"17.02.9-6.10.1","slurm-plugins":"17.02.9-6.10.1","slurm-sched-wiki":"17.02.9-6.10.1","slurm-slurmdb-direct":"17.02.9-6.10.1","slurm-slurmdbd":"17.02.9-6.10.1","slurm-sql":"17.02.9-6.10.1","slurm-torque":"17.02.9-6.10.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for HPC 12","name":"pdsh","purl":"pkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.33-7.5.17"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libpmi0":"17.02.9-6.10.1","libslurm29":"16.05.8.1-6.1","libslurm31":"17.02.9-6.10.1","pdsh":"2.33-7.5.17","perl-slurm":"17.02.9-6.10.1","slurm":"17.02.9-6.10.1","slurm-auth-none":"17.02.9-6.10.1","slurm-devel":"17.02.9-6.10.1","slurm-doc":"17.02.9-6.10.1","slurm-lua":"17.02.9-6.10.1","slurm-munge":"17.02.9-6.10.1","slurm-pam_slurm":"17.02.9-6.10.1","slurm-plugins":"17.02.9-6.10.1","slurm-sched-wiki":"17.02.9-6.10.1","slurm-slurmdb-direct":"17.02.9-6.10.1","slurm-slurmdbd":"17.02.9-6.10.1","slurm-sql":"17.02.9-6.10.1","slurm-torque":"17.02.9-6.10.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for HPC 12","name":"slurm","purl":"pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"17.02.9-6.10.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libpmi0":"17.02.9-6.10.1","libslurm29":"16.05.8.1-6.1","libslurm31":"17.02.9-6.10.1","pdsh":"2.33-7.5.17","perl-slurm":"17.02.9-6.10.1","slurm":"17.02.9-6.10.1","slurm-auth-none":"17.02.9-6.10.1","slurm-devel":"17.02.9-6.10.1","slurm-doc":"17.02.9-6.10.1","slurm-lua":"17.02.9-6.10.1","slurm-munge":"17.02.9-6.10.1","slurm-pam_slurm":"17.02.9-6.10.1","slurm-plugins":"17.02.9-6.10.1","slurm-sched-wiki":"17.02.9-6.10.1","slurm-slurmdb-direct":"17.02.9-6.10.1","slurm-slurmdbd":"17.02.9-6.10.1","slurm-sql":"17.02.9-6.10.1","slurm-torque":"17.02.9-6.10.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for HPC 12","name":"slurmlibs","purl":"pkg:rpm/suse/slurmlibs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"16.05.8.1-6.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for slurm fixes the following issues:\n\nSlurm was updated to 17.02.9 to fix a security bug, bringing new features and bugfixes\n(fate#323998 bsc#1067580).\n\nSecurity issue fixed:\n\n* CVE-2017-15566: Fix security issue in Prolog and Epilog by always prepending SPANK_ to\n  all user-set environment variables. (bsc#1065697)\n\nChanges in 17.02.9:\n\n   * When resuming powered down nodes, mark DOWN nodes right after\n     ResumeTimeout has been reached (previous logic would wait about one minute longer).\n   * Fix sreport not showing full column name for TRES Count.\n   * Fix slurmdb_reservations_get() giving wrong usage data when job's spanned\n     reservation that was modified.\n   * Fix sreport reservation utilization report showing bad data.\n   * Show all TRES' on a reservation in sreport reservation utilization report\n     by default.\n   * Fix sacctmgr show reservation handling 'end' parameter.\n   * Work around issue with sysmacros.h and gcc7 / glibc 2.25.\n   * Fix layouts code to only allow setting a boolean.\n   * Fix sbatch --wait to keep waiting even if a message timeout occurs.\n   * CRAY - If configured with NodeFeatures=knl_cray and there are non-KNL\n     nodes which include no features the slurmctld will abort without\n     this patch when attemping strtok_r(NULL).\n   * Fix regression in 17.02.7 which would run the spank_task_privileged as\n     part of the slurmstepd instead of it's child process.\n\nChanges in 17.02.8:\n\n   * Add 'slurmdbd:' to the accounting plugin to notify message is from dbd\n    instead of local.\n   * mpi/mvapich - Buffer being only partially cleared. No failures observed.\n   * Fix for job  --switch option on dragonfly network.\n   * In salloc with  --uid option, drop supplementary groups before changing UID.\n   * jobcomp/elasticsearch - strip any trailing slashes from JobCompLoc.\n   * jobcomp/elasticsearch - fix memory leak when transferring generated buffer.\n   * Prevent slurmstepd ABRT when parsing gres.conf CPUs.\n   * Fix sbatch --signal to signal all MPI ranks in a step instead of just those\n     on node 0.\n   * Check multiple partition limits when scheduling a job that were previously\n     only checked on submit.\n   * Cray: Avoid running application/step Node Health Check on the external\n     job step.\n   * Optimization enhancements for partition based job preemption.\n   * Address some build warnings from GCC 7.1, and one possible memory leak if\n     /proc is inaccessible.\n   * If creating/altering a core based reservation with scontrol/sview on a\n     remote cluster correctly determine the select type.\n   * Fix autoconf test for libcurl when clang is used.\n   * Fix default location for cgroup_allowed_devices_file.conf to use correct\n     default path.\n   * Document NewName option to sacctmgr.\n   * Reject a second PMI2_Init call within a single step to prevent slurmstepd\n     from hanging.\n   * Handle old 32bit values stored in the database for requested memory\n     correctly in sacct.\n   * Fix memory leaks in the task/cgroup plugin when constraining devices.\n   * Make extremely verbose info messages debug2 messages in the task/cgroup\n     plugin when constraining devices.\n   * Fix issue that would deny the stepd access to /dev/null where GRES has a\n    'type' but no file defined.\n   * Fix issue where the slurmstepd would fatal on job launch if you have no\n     gres listed in your slurm.conf but some in gres.conf.\n   * Fix validating time spec to correctly validate various time formats.\n   * Make scontrol work correctly with job update timelimit [+|-]=.\n   * Reduce the visibily of a number of warnings in _part_access_check.\n   * Prevent segfault in sacctmgr if no association name is specified for\n     an update command.\n   * burst_buffer/cray plugin modified to work with changes in Cray UP05\n     software release.\n   * Fix job reasons for jobs that are violating assoc MaxTRESPerNode limits.\n   * Fix segfault when unpacking a 16.05 slurm_cred in a 17.02 daemon.\n   * Fix setting TRES limits with case insensitive TRES names.\n   * Add alias for xstrncmp() -- slurm_xstrncmp().\n   * Fix sorting of case insensitive strings when using xstrcasecmp().\n   * Gracefully handle race condition when reading /proc as process exits.\n   * Avoid error on Cray duplicate setup of core specialization.\n   * Skip over undefined (hidden in Slurm) nodes in pbsnodes.\n   * Add empty hashes in perl api's slurm_load_node() for hidden nodes.\n   * CRAY - Add rpath logic to work for the alpscomm libs.\n   * Fixes for administrator extended TimeLimit (job reason & time limit reset).\n   * Fix gres selection on systems running select/linear.\n   * sview: Added window decorator for maximize,minimize,close buttons for all\n     systems.\n   * squeue: interpret negative length format specifiers as a request to\n     delimit values with spaces.\n   * Fix the torque pbsnodes wrapper script to parse a gres field with a type\n     set correctly.\n\nThis update also contains pdsh rebuilt against the new libslurm version.\n\n","id":"SUSE-SU-2017:3311-1","modified":"2017-12-14T14:51:03Z","published":"2017-12-14T14:51:03Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20173311-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1007053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1031872"},{"type":"REPORT","url":"https://bugzilla.suse.com/1041706"},{"type":"REPORT","url":"https://bugzilla.suse.com/1065697"},{"type":"REPORT","url":"https://bugzilla.suse.com/1067580"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15566"}],"related":["CVE-2017-15566"],"summary":"Security update for slurm","upstream":["CVE-2017-15566"]}