July 2024
CVE-2024-6387 - Qualys Security Advisory - Update Advisory
Additional information
- For clients running an Ubuntu Linux distribution, see the Ubuntu Security Notice for this issue.
- For clients running a Rocky Linux distribution, see the Rocky Linux news page discussing this issue.
- For clients running a CentOS Linux distribution, see the CentOS documentation for this issue.
- Windows is not known to be affected by this issue at time of publishing.
SUNK/Slurm User Guidance
Clients who are not on a CoreWeave-managed instance of SUNK and who meet the criteria below should take action to ensure that SUNK is patched againstCVE-2024-6387:
- Are using SUNK versions
3.20.0through4.3.0 - Are using Ubuntu images in SUNK of
22.04or higher
- Add the following items to the
s6configuration for both login and compute Nodes in the chartvalues.yamlbeing used to deploy CoreWeave’s Slurm chart:
- Deploy these changes (if using ArgoCD, sync the changes with the cluster).
If using custom build images for SUNK, these commands can be integrated into the image build instead.
November 2023
CVE-2023-23583 - INTEL-SA-00950 Update Advisory
CoreWeave’s Vulnerability Management Team is closely monitoring the situation and is dedicated to providing timely updates if deemed necessary. If required, updates to this page will be posted.
December 2022
CVE-2022-42475
FortiGuard Labs has confirmed at least one instance of vulnerability CVE-2022-42475 being exploited in the wild. Given the high value (CVE critical severity rating 9.3) and relatively low complexity of this vulnerability, CoreWeave strongly recommends upgrading to an unaffected version of FortiOS on an accelerated patch schedule, according to vendor recommendations.
Vulnerability checks for CVE-2022-42475 are available from a variety of sources. Please use caution when running any script or application to ensure it is safe.
At this time there is no impact to CoreWeave’s platform, however customers who have FortiOS running within their environment are advised to review the vendor-recommended mitigations, and take appropriate self measures to upgrade their deployments and evaluate their systems for any indicators of compromise. Our cyber security team is closely monitoring the situation, and will provide important updates should more information become available.