Fedora Linux 8579 Published by

A pmix security update has been released for Fedora 37.



[SECURITY] Fedora 37 Update: pmix-4.1.3-1.fc37


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2023-155d2f22f1
2023-10-04 02:59:33.979957
--------------------------------------------------------------------------------

Name : pmix
Product : Fedora 37
Version : 4.1.3
Release : 1.fc37
URL : https://pmix.org/
Summary : Process Management Interface Exascale (PMIx)
Description :
The Process Management Interface (PMI) has been used for quite some time as
a means of exchanging wireup information needed for interprocess
communication. Two versions (PMI-1 and PMI-2) have been released as part of
the MPICH effort. While PMI-2 demonstrates better scaling properties than its
PMI-1 predecessor, attaining rapid launch and wireup of the roughly 1M
processes executing across 100k nodes expected for exascale operations remains
challenging.

PMI Exascale (PMIx) represents an attempt to resolve these questions by
providing an extended version of the PMI standard specifically designed to
support clusters up to and including exascale sizes. The overall objective of
the project is not to branch the existing pseudo-standard definitions - in
fact, PMIx fully supports both of the existing PMI-1 and PMI-2 APIs - but
rather to (a) augment and extend those APIs to eliminate some current
restrictions that impact scalability, and (b) provide a reference
implementation of the PMI-server that demonstrates the desired level of
scalability.

--------------------------------------------------------------------------------
Update Information:

Security fix for CVE-2023-41915
--------------------------------------------------------------------------------
ChangeLog:

* Thu Sep 14 2023 Michel Lind [salimma@fedoraproject.org] - 4.1.3-1
- Fix CVE-2023-41915
- Update upstream source URL; pmix/pmix redirects to openpmix/openpmix
- Use SPDX license identifier
* Fri Jul 21 2023 Fedora Release Engineering [releng@fedoraproject.org] - 4.1.2-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Fri Jan 20 2023 Fedora Release Engineering [releng@fedoraproject.org] - 4.1.2-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2238898 - CVE-2023-41915 pmix: race condition allows attackers to obtain ownership of arbitrary files
https://bugzilla.redhat.com/show_bug.cgi?id=2238898
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2023-155d2f22f1' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------