Slurm
Workload manager and job scheduler for HPC clusters
Slurm coordinated a 7-CVE security drop across three active branches, including a privilege escalation and SQL injection.
◆Recent moves
- 13d ago
Slurm 26.05.4: 7 CVEs patched including privilege escalation and SQL injection
v26.05.4 closes 7 CVEs on the current release branch — including a privilege escalation (operator → admin via accounting DB) and SQL injection via cluster names — alongside the usual bug fix sweep of memory leaks, crash paths, and heterogeneous job handling. For HPC clusters with multiple user roles, the privilege escalation fix is the most operationally critical.
View source ↗ - 13d ago
Slurm 25.11.8: CVE backport security release
v25.11.8 backports the same CVE set to the previous stable branch, plus a QOS-based preemption segfault fix. Sites running 25.11.x that cannot upgrade to 26.05 get security coverage without a major version jump — the expected pattern in Slurm's multi-branch maintenance model.
View source ↗ - 13d ago
Slurm 25.05.9: CVE backport security release
v25.05.9 backports the CVE set to the older 25.05.x branch — the same coordinated security response as 25.11.8 and 26.05.4, ensuring sites on any of the three supported release lines receive the same security coverage simultaneously.
View source ↗ - 1mo ago
v26.05.3
v26.05.3 adds support for external nodes in heterogeneous jobs — including batch submission via sbatch and REST interface — enabling cloud-burst HPC scenarios where some job components run on external (non-Slurm-controlled) nodes. The surrounding bug fixes address backfill correctness, licensing, JWT authentication, and a range of crash paths.
View source ↗ - 2mo ago
v26.05.2
v26.05.2 addresses a significant burst of reliability issues: a QOS pointer dereference after assoc_mgr update, PMIx task count handling, a deadlock in the extern slurmstepd during X11 forwarding, and node-count statistics overcounting. These are the kinds of fixes that accumulated during the 26.05.0 major release ramp-up.
View source ↗ - 2mo ago
v25.11.7
v25.11.7 resolves a QOS preemption segfault, a license-loss regression on job requeue, and an accounting storage lock contention issue causing performance regressions. The metrics endpoint redirect for standby controllers (303 → primary) is a useful operational improvement for multi-controller setups.
View source ↗