CVE-2022-29501
Description
SchedMD Slurm versions 20.11.x through 21.08.x contain an incorrect access control vulnerability leading to privilege escalation and arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SchedMD Slurm versions 20.11.x through 21.08.x contain an incorrect access control vulnerability leading to privilege escalation and arbitrary code execution.
Vulnerability
In SchedMD Slurm versions 20.11.x through 21.08.x, an incorrect access control vulnerability exists [1][2]. The exact component is not publicly detailed, but the CVE description confirms it leads to privilege escalation and code execution.
Exploitation
An attacker with low privileges can exploit this vulnerability. The specific attack vector is not disclosed in available references. According to the CVE description, exploitation results in privilege escalation.
Impact
Successful exploitation allows an attacker to escalate privileges and execute arbitrary code on the Slurm cluster, compromising confidentiality, integrity, and availability.
Mitigation
No specific fix is available in the referenced sources. Users should monitor SchedMD's security advisories for updates. As of the publication date, no patch has been released.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
65- osv-coords63 versionspkg:rpm/opensuse/pdsh&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/pdsh&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/pdsh_slurm_20_02&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/pdsh_slurm_20_02&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/pdsh_slurm_20_11&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/pdsh_slurm_20_11&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/pdsh_slurm_22_05&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/pdsh_slurm_22_05&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm_18_08&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/slurm_18_08&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm_20_02&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/slurm_20_02&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm_20_11&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/slurm_20_11&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm_22_05&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/slurm_22_05&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/slurm&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP3pkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP4pkg:rpm/suse/pdsh_slurm_18_08&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_20_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/pdsh_slurm_20_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/pdsh_slurm_20_02&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_20_11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP3pkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP4pkg:rpm/suse/slurm_18_08&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/slurm_18_08&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/slurm_18_08&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_20_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/slurm_20_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/slurm_20_02&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP3pkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP4pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP3
< 2.34-150300.35.2+ 62 more
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 18.08.9-150000.1.17.1
- (no CPE)range: < 18.08.9-150000.1.17.1
- (no CPE)range: < 20.02.7-150100.3.24.1
- (no CPE)range: < 20.02.7-150100.3.24.1
- (no CPE)range: < 20.11.9-150200.6.10.1
- (no CPE)range: < 20.11.9-150200.6.10.1
- (no CPE)range: < 22.05.5-150300.7.3.2
- (no CPE)range: < 22.05.5-150300.7.3.2
- (no CPE)range: < 20.11.9-150300.4.6.1
- (no CPE)range: < 20.11.9-150300.4.6.1
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-7.35.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-7.35.3
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-7.35.3
- (no CPE)range: < 2.34-7.35.3
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-7.35.5
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 18.08.9-150000.1.17.1
- (no CPE)range: < 18.08.9-150000.1.17.1
- (no CPE)range: < 18.08.9-3.17.1
- (no CPE)range: < 20.02.7-150100.3.24.1
- (no CPE)range: < 20.02.7-150100.3.24.1
- (no CPE)range: < 20.02.7-3.14.1
- (no CPE)range: < 20.11.9-150100.3.14.1
- (no CPE)range: < 20.11.9-150100.3.14.1
- (no CPE)range: < 20.11.9-150200.6.10.1
- (no CPE)range: < 20.11.9-150200.6.10.1
- (no CPE)range: < 20.11.9-3.11.1
- (no CPE)range: < 22.05.5-150100.3.3.1
- (no CPE)range: < 22.05.5-150100.3.3.1
- (no CPE)range: < 22.05.5-150200.5.3.2
- (no CPE)range: < 22.05.5-150200.5.3.2
- (no CPE)range: < 22.05.5-3.3.5
- (no CPE)range: < 22.05.5-150300.7.3.2
- (no CPE)range: < 22.05.5-150300.7.3.2
- (no CPE)range: < 18.08.9-150100.3.22.1
- (no CPE)range: < 18.08.9-150100.3.22.1
- (no CPE)range: < 20.02.7-150200.3.14.2
- (no CPE)range: < 20.02.7-150200.3.14.2
- (no CPE)range: < 17.11.13-150000.6.40.1
- (no CPE)range: < 17.11.13-150000.6.40.1
- (no CPE)range: < 17.02.11-6.53.1
- (no CPE)range: < 20.11.9-150300.4.6.1
Patches
0No patches discovered yet.
Vulnerability mechanics
Root cause
"Incorrect access control in SchedMD Slurm allows unauthorized privilege escalation."
Attack vector
An attacker with low-privileged access to a Slurm cluster can exploit incorrect access control checks to perform actions normally restricted to administrators [ref_id=1]. The advisory does not detail the exact network path or payload shape, but the impact is described as escalation of privileges and code execution [ref_id=1]. The vulnerability affects Slurm versions 21.08.x through 20.11.x.
Affected code
The advisory does not specify exact functions or files. The vulnerability is described as "Incorrect Access Control" in SchedMD Slurm versions 21.08.x through 20.11.x, leading to escalation of privileges and code execution [ref_id=1]. No patch diff or specific code paths are identified in the supplied bundle.
What the fix does
The advisory does not include a specific patch diff. The vendor (SchedMD) has addressed this vulnerability in subsequent releases, as indicated by the release notes for versions 25.11.6, 25.05.8, and 26.05.0rc1 [ref_id=1]. Users should upgrade to a patched version of Slurm to remediate the incorrect access control flaw.
Preconditions
- authAttacker must have a low-privileged account on the Slurm cluster
- configAffected Slurm version between 20.11.x and 21.08.x
Generated on May 28, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
7- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXLOI3ERTKMZR2KWNRN7OR5S55VPWENH/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y6B7OWVNVCJUDE6VDWGCBUWMRCRETAO3/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YBI4NFDGGMBKWG4EMSZL5UHATDCLPCQW/mitrevendor-advisoryx_refsource_FEDORA
- www.debian.org/security/2022/dsa-5166mitrevendor-advisoryx_refsource_DEBIAN
- lists.schedmd.com/pipermail/slurm-announce/mitrex_refsource_MISC
- www.schedmd.com/news.phpmitrex_refsource_MISC
- www.schedmd.com/news.phpmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.