PT-2024-10822 · Gentoo+1 · Gentoo+1

Michael Orlitzky

·

Published

2024-01-15

·

Updated

2024-01-22

·

CVE-2020-36770

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Slurm versions through 22.05.3
Description The issue arises from the pkg postinst in the Gentoo ebuild for Slurm, which unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could be exploited by the slurm user to become the owner of root-owned files.
Recommendations For Slurm versions through 22.05.3, consider restricting the slurm user's access to sensitive files until a patch is available. As a temporary workaround, avoid using the pkg postinst script in the Gentoo ebuild for Slurm, or ensure that the chown command is not executed unnecessarily. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2020-36770

Affected Products

Gentoo
Slurm