<?xml version="1.0" encoding="UTF-8"?>

<!-- AUTOGENERATED FILE. DO NOT EDIT. -->

<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:cluster-toolkit-security-bulletins</id>
  <title>Cluster Toolkit - Security Bulletins</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/cluster-toolkit-security-bulletins.xml"/>
  <author>
    <name>Google Cloud Documentation</name>
  </author>
  <updated>2026-09-07T15:55:51.736391+00:00</updated>


  <entry>
    <title>GCP-2026-060</title>
    <id>tag:google.com,2016:cluster-toolkit-security-bulletins#gcp-2026-060</id>
    <updated>2026-09-07T15:55:51.736391+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/cluster-toolkit/docs/security-bulletins#gcp-2026-060"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-09-07</p><h3 class="hide-from-toc" data-text="Description" id="description" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A security flaw in the Slurm <code dir="ltr" translate="no">sbcast</code> tool
        (CVE-2026-65107) lets shared library files bypass security checks and
        can crash nodes in your cluster.</p>
<h4 data-text="What should I do?" id="what-should-i-do" tabindex="-1">What should I do?</h4>
<p>Google updated the OS images that Cluster Toolkit supports with the
        necessary patches for CVE-2026-65107. If a node hasn't been recreated
        since September 7, 2026, then the node is vulnerable. To update the node
        with the latest OS image, do one of the following:</p>
<ul>
<li><strong><a href="/cluster-toolkit/docs/slurm/manage-static-nodes#update-images">
            Power down static nodes</a></strong>. Slurm recreates the node with
            the patched OS image when you submit new jobs.</li>
<li><strong><a href="/cluster-toolkit/docs/slurm/reconfigure-cluster#reconfigure-partitions-on-running-cluster">
            Reconfigure a running cluster</a></strong>. In the deployment
            blueprint for your cluster, update the image family and redeploy the
            cluster.</li>
</ul>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>Slurm CVE-2026-65107</p>
</td>
<td>High</td>
<td>
<a href="https://www.cve.org/CVERecord?id=CVE-2026-65107">CVE-2026-65107</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>
</feed>
