Security bulletins

This document describes all security bulletins that are related to Cluster Toolkit. Use these bulletins to identify known vulnerabilities and apply the recommended mitigations or fixes to protect your infrastructure.

To get the latest security bulletins delivered to you, do one of the following:

  • Add the URL of this page to your feed reader.
  • Add the feed URL directly to your feed reader: /feeds/cluster-toolkit-security-bulletins.xml

GCP-2026-062

Published: 2026-09-11

Description

Description Severity Notes

Multiple security vulnerabilities were discovered in Slurm that affect Cluster Toolkit blueprints that reference specific image versions. These vulnerabilities affect the slurmstepd daemon, RPC request handling, and the accounting database.

What should I do?

To mitigate these vulnerabilities, upgrade to Cluster Toolkit version v1.103.0 or later, which upgrades Slurm to version 25.11.8 and updates pinned image references.

New deployments that use the updated blueprints automatically use the patched image versions.

For existing deployments, you must destroy and recreate your VMs or cluster by using the updated blueprint. Redeploying directly to a running cluster does not update running VMs and can cause version mismatches.

What vulnerabilities are being addressed?

This bulletin resolves multiple vulnerabilities in Slurm. For more information, see the SchedMD Slurm 25.11 release notes.

High

GCP-2026-060

Published: 2026-09-07

Description

Description Severity Notes

A security flaw in the Slurm sbcast tool (CVE-2026-65107) lets shared library files bypass security checks and can crash nodes in your cluster.

What should I do?

Google updated the supported OS image families (Automated Cloud Images) with patches for CVE-2026-65107 on September 5, 2026. If a node has not been recreated since September 7, 2026, then the node is vulnerable. To apply the patch, do one of the following:

What vulnerabilities are being addressed?

Slurm CVE-2026-65107

High CVE-2026-65107