Junglewise Threat Intelligence

CVE-2026-65107: Slurm multiple vulnerabilities in Cluster Toolkit

CVE-2026-65107 · Severity: high · Published 2026-09-11

Executive brief

Multiple critical security vulnerabilities were discovered in Slurm, a widely-used job scheduling and resource management system for high-performance computing clusters. These vulnerabilities affect the slurmstepd daemon, RPC request handling, and the accounting database in Google Cloud's Cluster Toolkit. Exploitation could allow attackers to execute unauthorized code, escalate privileges, or disrupt cluster operations.

Technical details

Multiple vulnerabilities were discovered in Slurm affecting critical components: the slurmstepd daemon (which manages job step execution), RPC request handling (for inter-node communication), and the accounting database. The vulnerabilities span eight CVEs (CVE-2026-65107, CVE-2026-65108, CVE-2026-65109, CVE-2026-65138, CVE-2026-65139, CVE-2026-65140, CVE-2026-65165, CVE-2026-65168) and include issues such as shared library bypass in the sbcast tool and flaws in daemon communication protocols. These issues affect Slurm installations deployed via Google Cloud's Cluster Toolkit when using specific vulnerable image versions. Fixes are available through updated Cluster Toolkit blueprints and patched Slurm versions.

Affected products

  • SchedMD Slurm Multiple versions affected (specific versions referenced in Cluster Toolkit blueprints)

Timeline

  • 2026-09-11: disclosed: GCP-2026-062 published; GCP-2026-060 published earlier on 2026-09-04 referencing CVE-2026-65107

References

Related threats