Security bulletins

This document describes all security bulletins that are related to Cluster Director. Use these bulletins to identify known vulnerabilities and apply the recommended mitigations or fixes to protect your infrastructure.

To get the latest security bulletins delivered to you, do one of the following:

  • Add the URL of this page to your feed reader.
  • Add the feed URL directly to your feed reader: https://cloud.google.com/feeds/cluster-director-security-bulletins.xml

GCP-2026-060

Published: 2026-09-04

Description

Description Severity Notes

A security flaw in the Slurm sbcast tool (CVE-2026-65107) lets shared library files bypass security checks and can crash nodes in your cluster.

What should I do?

Google updated the default OS image families (NVIDIA driver version 580) for Cluster Director on August 27, 2026, to resolve CVE-2026-65107. Other OS images families (NVIDIA driver version 570) won't receive this patch. For more information, see Image family release notes.

To protect your clusters, complete the following steps:

  1. Verify the OS image family that your compute and login nodes use.
  2. Based on the OS image family, do one of the following:

What vulnerabilities are being addressed?

Slurm CVE-2026-65107

High CVE-2026-65107