pmix-2.2.5-3.el8

エラータID: AXSA:2024-8272:02

Release date: 
Saturday, June 15, 2024 - 08:34
Subject: 
pmix-2.2.5-3.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The Process Management Interface (PMI) provides process management functions for MPI implementations. PMI Exascale (PMIx) provides an extended version of the PMI standard specifically designed to support clusters up to and including exascale sizes.

Security Fix(es):

* pmix: race condition allows attackers to obtain ownership of arbitrary files (CVE-2023-41915)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 8.10 Release Notes linked from the References section.

CVE-2023-41915
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. pmix-2.2.5-3.el8.src.rpm
    MD5: 2001f92cb78f6ba7a2a070be0cc68a0e
    SHA-256: 3239afe1bbba22e176eca5640a5d6509d4b2a156589759027dcf8e0b98afc163
    Size: 1.10 MB

Asianux Server 8 for x86_64
  1. pmix-2.2.5-3.el8.i686.rpm
    MD5: 111a745396119dcc05792fb477623cf4
    SHA-256: 7668442a7b6d300f96285de9a44ad71880723b7254eba869d6c9a56882dbe1a0
    Size: 780.23 kB
  2. pmix-2.2.5-3.el8.x86_64.rpm
    MD5: 9af88499a634e59b9f64f8f38ae81ab3
    SHA-256: 6d911c49a4649433fe5807f021f22893d202886f26244be85bf5b7d3eb65a72d
    Size: 735.07 kB
  3. pmix-devel-2.2.5-3.el8.i686.rpm
    MD5: 9b630e6b59f01d1acf726374b548a5c8
    SHA-256: dcc3159d29819ca5d8b2233dc0ba0e6d5556d1eac3ee941a6e8aba10c1e6c624
    Size: 58.43 kB
  4. pmix-devel-2.2.5-3.el8.x86_64.rpm
    MD5: be0eb2d0f93ec1cd5122c24cd5d8e185
    SHA-256: 0570cbd8a574604fb9e8c702479481f3985d39c2fd2ef5f473d98d138452ea12
    Size: 58.44 kB