(3.16.0 and earlier) Security vulnerabilities in Slurm: CVE‐2026‐65107, CVE‐2026‐65108, CVE‐2026‐65109, CVE‐2026‐65138, CVE‐2026‐65139, CVE‐2026‐65140, CVE‐2026‐65165, CVE‐2026‐65168
- Dominant language
- Python
- Stars
- 888
- Forks
- 314
- Avg merge
- 1d 10h
- Merged PRs (30d)
- 43
Description
### The issue
AWS ParallelCluster clusters are impacted by the following Slurm CVEs: CVE-2026-65107, CVE-2026-65108, CVE-2026-65109, CVE-2026-65138, CVE-2026-65139, CVE-2026-65140, CVE-2026-65165, CVE-2026-65168. All Slurm versions prior to 25.05.9, 25.11.8, and 26.05.4 are impacted.
### Affected ParallelCluster versions, OSes and schedulers
All ParallelCluster versions <=3.16.0 on all OSes are impacted.
### Mitigation
To patch your existing clusters, you can update Slurm in place to version 25.11.8 by following [the procedure on GitHub](https://github.com/aws/aws-parallelcluster/wiki/Upgrade-Slurm-in-an-AWS-ParallelCluster-cluster). This applies to all currently supported ParallelCluster versions according to the [support policy](https://docs.aws.amazon.com/parallelcluster/latest/ug/support-policy.html). If you are running a end of support ParallelCluster version, we recommend recreating your clusters using a supported ParallelCluster version.
Contributor guide
Research direction
No repository files, tests, or entry points are named. Start by reviewing the listed CVEs and the linked Upgrade Slurm procedure, then determine whether this issue tracks a code change or only communicates mitigation. Done is unclear because the report specifies affected versions and an operational workaround but no repository change or acceptance test.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, python
- Domain
- cloud, infrastructure, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100