Security Advisory Desk
unratedQCS priority 70/100Google Cloud

GCP-2026-062

Multiple serious security flaws were found in Slurm, a workload manager used in Google Cloud's Cluster Toolkit with certain image versions. These issues affect key components that manage job steps, remote procedure communications, and accounting databases, risking unauthorized access or disruption. Users should follow the Cluster Toolkit security bulletin instructions to address these vulnerabilities promptly.

Published 11/9/2026, 2:57:02 pmVerified 11/9/2026, 9:04:42 pmRevision 1
Google Cloud unrated network security advisory visual

In plain language

What this advisory means

Multiple serious security flaws were found in Slurm, a workload manager used in Google Cloud's Cluster Toolkit with certain image versions. These issues affect key components that manage job steps, remote procedure communications, and accounting databases, risking unauthorized access or disruption. Users should follow the Cluster Toolkit security bulletin instructions to address these vulnerabilities promptly.

Technical explanation

How the issue affects the environment

Several vulnerabilities have been identified in Slurm's components, including the slurmstepd daemon responsible for job step management, RPC (Remote Procedure Call) request handling mechanisms, and the accounting database of the Cluster Toolkit blueprints referencing specific Slurm image versions. The vulnerabilities expose potential risks such as unauthorized command execution, exploitation of RPC calls, and compromise of accounting data integrity, affecting cluster job execution reliability and data security in affected image versions.

Operational impact

Why teams should care

The vulnerabilities could lead to unauthorized access or manipulation of cluster job execution and accounting data. This may result in service disruption, loss of data integrity, or unauthorized resource usage within Google Cloud environments using affected Cluster Toolkit blueprints, potentially impacting operational continuity and increasing security compliance risks.

Immediate action

Users should consult the Cluster Toolkit security bulletin linked in the advisory for detailed instructions and follow recommended update procedures or configuration changes to mitigate the vulnerabilities affecting specific image versions of Slurm used in their clusters.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • Official Google Cloud Security Bulletin published on 2026-09-11
  • Identification of multiple Slurm vulnerabilities affecting slurmstepd daemon, RPC handling, and accounting database
  • Reference to CVEs: CVE-2026-65107, CVE-2026-65108, CVE-2026-65109, CVE-2026-65138, CVE-2026-65139, CVE-2026-65140, CVE-2026-65165, CVE-2026-65168
  • Instruction to follow Cluster Toolkit security bulletin for remediation

Authoritative reference

Google Cloud Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source