Search CVE reports
1351 – 1360 of 50681 results
[Fix heap over-read when unpacking a malformed forward data RPC in slurmd. Fix a slurmd crash when handling a malformed forward data RPC with a missing socket address]
1 affected package
slurm-wlm
| Package | 22.04 LTS |
|---|---|
| slurm-wlm | Needs evaluation |
[Fix slurmstepd removing files outside the container spool directory when cleaning up an OCI containe, Fix slurmstepd leaving OCI container spool directories behind when ContainerPath contains a task id pattern]
1 affected package
slurm-wlm
| Package | 22.04 LTS |
|---|---|
| slurm-wlm | Needs evaluation |
[Fix a slurmstepd stack overflow when a job environment contains an oversized SPANK option variable]
1 affected package
slurm-wlm
| Package | 22.04 LTS |
|---|---|
| slurm-wlm | Needs evaluation |
[Fix sbcast shared objects skipping credential verification, Fix possible slurmd crash on invalid sbcast filenames]
1 affected package
slurm-wlm
| Package | 22.04 LTS |
|---|---|
| slurm-wlm | Needs evaluation |
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established...
10 affected packages
golang-1.17, golang-1.20, golang-1.21, golang-1.22, golang-1.23...
| Package | 22.04 LTS |
|---|---|
| golang-1.17 | Needs evaluation |
| golang-1.20 | Needs evaluation |
| golang-1.21 | Needs evaluation |
| golang-1.22 | Needs evaluation |
| golang-1.23 | Needs evaluation |
| golang-1.24 | Needs evaluation |
| golang-1.25 | Not in release |
| golang-1.26 | Not in release |
| golang-1.27 | Not in release |
| golang-defaults | Needs evaluation |
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then,...
10 affected packages
golang-1.17, golang-1.20, golang-1.21, golang-1.22, golang-1.23...
| Package | 22.04 LTS |
|---|---|
| golang-1.17 | Needs evaluation |
| golang-1.20 | Needs evaluation |
| golang-1.21 | Needs evaluation |
| golang-1.22 | Needs evaluation |
| golang-1.23 | Needs evaluation |
| golang-1.24 | Needs evaluation |
| golang-1.25 | Not in release |
| golang-1.26 | Not in release |
| golang-1.27 | Not in release |
| golang-defaults | Needs evaluation |
Not in release
libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers to inject arbitrary metadata by exploiting 64-bit box size truncation to size_t on 32-bit platforms. Attackers...
1 affected package
jpeg-xl
| Package | 22.04 LTS |
|---|---|
| jpeg-xl | Not in release |
Not in release
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected...
1 affected package
libnginx-mod-js
| Package | 22.04 LTS |
|---|---|
| libnginx-mod-js | Not in release |
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor...
1 affected package
util-linux
| Package | 22.04 LTS |
|---|---|
| util-linux | Needs evaluation |
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep...
1 affected package
util-linux
| Package | 22.04 LTS |
|---|---|
| util-linux | Needs evaluation |