<?xml version="1.0" encoding="UTF-8"?>

<!-- AUTOGENERATED FILE. DO NOT EDIT. -->

<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:cluster-toolkit-security-bulletins</id>
  <title>Cluster Toolkit - Security Bulletins</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/cluster-toolkit-security-bulletins.xml"/>
  <author>
    <name>Google Cloud Documentation</name>
  </author>
  <updated>2026-09-11T14:56:04.495300+00:00</updated>


  <entry>
    <title>GCP-2026-062</title>
    <id>tag:google.com,2016:cluster-toolkit-security-bulletins#gcp-2026-062</id>
    <updated>2026-09-11T14:56:04.495300+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/cluster-toolkit/docs/security-bulletins#gcp-2026-062"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-09-11</p><h3 class="hide-from-toc" data-text="Description" id="description" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Multiple security vulnerabilities were discovered in Slurm that
        affect Cluster Toolkit blueprints that reference specific image
        versions. These vulnerabilities affect the <code dir="ltr" translate="no">slurmstepd</code>
        daemon, RPC request handling, and the accounting database.</p>
<h4 data-text="What should I do?" id="what-should-i-do" tabindex="-1">What should I do?</h4>
<p>To mitigate these vulnerabilities, upgrade to
        <a href="https://docs.cloud.google.com/cluster-toolkit/docs/release-notes#v1.103.0">
        Cluster Toolkit version v1.103.0</a> or later, which upgrades
        Slurm to version 25.11.8 and updates pinned image references.</p>
<p>New deployments that use the updated blueprints automatically use
        the patched image versions.</p>
<p>For existing deployments, you must destroy and recreate your VMs or
        cluster by using the updated blueprint. Redeploying directly to a
        running cluster does not update running VMs and can cause version
        mismatches.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>This bulletin resolves multiple vulnerabilities in Slurm. For more
        information, see the SchedMD
        <a href="https://github.com/SchedMD/slurm/blob/slurm-25.11/CHANGELOG/slurm-25.11.md">
          Slurm 25.11 release notes</a>.</p>
</td>
<td>High</td>
<td>
<ul>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-65107">CVE-2026-65107</a></li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-65108">CVE-2026-65108</a></li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-65109">CVE-2026-65109</a></li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-65138">CVE-2026-65138</a></li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-65139">CVE-2026-65139</a></li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-65140">CVE-2026-65140</a></li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-65165">CVE-2026-65165</a></li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-65168">CVE-2026-65168</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-060</title>
    <id>tag:google.com,2016:cluster-toolkit-security-bulletins#gcp-2026-060</id>
    <updated>2026-09-11T14:56:04.495300+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/cluster-toolkit/docs/security-bulletins#gcp-2026-060"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-09-07</p><h3 class="hide-from-toc" data-text="Description" id="description_1" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A security flaw in the Slurm <code dir="ltr" translate="no">sbcast</code> tool
        (CVE-2026-65107) lets shared library files bypass security checks and
        can crash nodes in your cluster.</p>
<h4 data-text="What should I do?" id="what-should-i-do_1" tabindex="-1">What should I do?</h4>
<p>Google updated the supported OS image families (Automated Cloud
        Images) with patches for CVE-2026-65107 on September 5, 2026. If a node
        has not been recreated since September 7, 2026, then the node is
        vulnerable. To apply the patch, do one of the following:</p>
<ul>
<li><strong><a href="https://docs.cloud.google.com/cluster-toolkit/docs/slurm/manage-static-nodes#update-images">
            Power down static nodes</a></strong>. Slurm recreates the node with
            the patched OS image when you submit new jobs.</li>
<li><strong><a href="https://docs.cloud.google.com/cluster-toolkit/docs/slurm/reconfigure-cluster#reconfigure-partitions-on-running-cluster">
            Reconfigure a running cluster</a></strong>. In the deployment
            blueprint for your cluster, ensure the image family points to the
            latest image and redeploy the cluster.</li>
</ul>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_1" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>Slurm CVE-2026-65107</p>
</td>
<td>High</td>
<td>
<a href="https://www.cve.org/CVERecord?id=CVE-2026-65107">CVE-2026-65107</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>


</feed>
