SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).
CVE-2018-10995
Score 5.3 from GitHub Security Advisory published 2022-05-13. NVD baseline CVSS 5.3; sources differ by 0.0.
- Lower severity and no public exploit yet
A fix is available — apply it.
- CVSS v3
- 5.3
- EG Score
- 5.3(medium)
- EG Risk
- 29(Track)EG Risk 29/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity53% × 45%Exploitation2% × 40%Automatability30% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 2%
- EPSS %ILE
- 76%
- KEV
- Not listed
Published
May 30, 2018
Last Modified
November 21, 2024
References (10)
- cve@mitrehttps://lists.debian.org/debian-lts-announce/2018/07/msg00029.html
- cve@mitrehttps://lists.debian.org/debian-lts-announce/2018/08/msg00008.html
- cve@mitrehttps://lists.schedmd.com/pipermail/slurm-announce/2018/000008.html
- cve@mitrehttps://www.debian.org/security/2018/dsa-4254
- cve@mitrehttps://www.schedmd.com/news.php?id=203
- af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2018/07/msg00029.html
- af854a3a-2127-422b-91ae-364da2661108https://lists.debian.org/debian-lts-announce/2018/08/msg00008.html
- af854a3a-2127-422b-91ae-364da2661108https://lists.schedmd.com/pipermail/slurm-announce/2018/000008.html
- af854a3a-2127-422b-91ae-364da2661108https://www.debian.org/security/2018/dsa-4254
- af854a3a-2127-422b-91ae-364da2661108https://www.schedmd.com/news.php?id=203
Patch Availability(2)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | slurm-llnl-sview (2.6.5-1ubuntu0.1~esm6) @ trusty | 2026-05-28 | ubuntu |
| ubuntu | slurm-client-emulator (19.05.5-1ubuntu0.1~esm1) @ focal | 2026-05-28 | ubuntu |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(2 across 2 ecosystems)
Debian:8(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| slurm-llnl | 14.03.9-5, 14.03.9-5+deb8u1, 14.03.9-5+deb8u2 | 14.03.9-5+deb8u3 | — |
Debian:9(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| slurm-llnl | 16.05.9-1, 16.05.9-1+deb9u1 | 16.05.9-1+deb9u2 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Frequently asked(5)
What is CVE-2018-10995?
When was CVE-2018-10995 disclosed?
Is CVE-2018-10995 actively exploited?
What is the CVSS score of CVE-2018-10995?
How do I remediate CVE-2018-10995?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2018-10995
Is Your Infrastructure Affected by CVE-2018-10995?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.