OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "high", "binaries": [ { "binary_version": "2.1.1~rc1-1ubuntu0.1~esm1", "binary_name": "libpmi-pmix-dev" }, { "binary_version": "2.1.1~rc1-1ubuntu0.1~esm1", "binary_name": "libpmi1-pmix" }, { "binary_version": "2.1.1~rc1-1ubuntu0.1~esm1", "binary_name": "libpmi1-pmix-dbgsym" }, { "binary_version": "2.1.1~rc1-1ubuntu0.1~esm1", "binary_name": "libpmi2-pmix" }, { "binary_version": "2.1.1~rc1-1ubuntu0.1~esm1", "binary_name": "libpmi2-pmix-dbgsym" }, { "binary_version": "2.1.1~rc1-1ubuntu0.1~esm1", "binary_name": "libpmix-dev" }, { "binary_version": "2.1.1~rc1-1ubuntu0.1~esm1", "binary_name": "libpmix2" }, { "binary_version": "2.1.1~rc1-1ubuntu0.1~esm1", "binary_name": "libpmix2-dbgsym" } ], "priority_reason": "arbitrary file write, in some cases under UID 0" }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "high", "binaries": [ { "binary_version": "3.1.5-1ubuntu0.1~esm1", "binary_name": "libpmi-pmix-dev" }, { "binary_version": "3.1.5-1ubuntu0.1~esm1", "binary_name": "libpmi1-pmix" }, { "binary_version": "3.1.5-1ubuntu0.1~esm1", "binary_name": "libpmi1-pmix-dbgsym" }, { "binary_version": "3.1.5-1ubuntu0.1~esm1", "binary_name": "libpmi2-pmix" }, { "binary_version": "3.1.5-1ubuntu0.1~esm1", "binary_name": "libpmi2-pmix-dbgsym" }, { "binary_version": "3.1.5-1ubuntu0.1~esm1", "binary_name": "libpmix-dev" }, { "binary_version": "3.1.5-1ubuntu0.1~esm1", "binary_name": "libpmix2" }, { "binary_version": "3.1.5-1ubuntu0.1~esm1", "binary_name": "libpmix2-dbgsym" } ], "priority_reason": "arbitrary file write, in some cases under UID 0" }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "high", "binaries": [ { "binary_version": "4.1.2-2ubuntu1+esm1", "binary_name": "libpmix-bin" }, { "binary_version": "4.1.2-2ubuntu1+esm1", "binary_name": "libpmix-bin-dbgsym" }, { "binary_version": "4.1.2-2ubuntu1+esm1", "binary_name": "libpmix-dev" }, { "binary_version": "4.1.2-2ubuntu1+esm1", "binary_name": "libpmix2" }, { "binary_version": "4.1.2-2ubuntu1+esm1", "binary_name": "libpmix2-dbgsym" }, { "binary_version": "4.1.2-2ubuntu1+esm1", "binary_name": "python3-pmix" }, { "binary_version": "4.1.2-2ubuntu1+esm1", "binary_name": "python3-pmix-dbgsym" } ], "priority_reason": "arbitrary file write, in some cases under UID 0" }
{ "availability": "No subscription required", "ubuntu_priority": "high", "binaries": [ { "binary_version": "5.0.1-4.1build1", "binary_name": "libpmix-bin" }, { "binary_version": "5.0.1-4.1build1", "binary_name": "libpmix-bin-dbgsym" }, { "binary_version": "5.0.1-4.1build1", "binary_name": "libpmix-dev" }, { "binary_version": "5.0.1-4.1build1", "binary_name": "libpmix2t64" }, { "binary_version": "5.0.1-4.1build1", "binary_name": "libpmix2t64-dbgsym" }, { "binary_version": "5.0.1-4.1build1", "binary_name": "python3-pmix" }, { "binary_version": "5.0.1-4.1build1", "binary_name": "python3-pmix-dbgsym" } ], "priority_reason": "arbitrary file write, in some cases under UID 0" }