Skip to content

Use of insecure temporary file when running in LSF job / with jsrun

Low
EnricoMi published GHSA-47wv-vhj2-g66m Mar 23, 2022

Package

pip horovod (pip)

Affected versions

<=0.23.0

Patched versions

0.24.0

Description

Impact

The insecure tempfile.mktemp() is used when Horovod is run in an LSF job with jsrun. In that situation, a jsrun rank file is created with mktemp, which could be hijacked by another process to read or manipulate the content.

This issue does not impact the use of MPI, Gloo, Spark or Ray.

Patches

The problem has been fixed in b96ecae4.

Workarounds

The rank file is not created when binding_args are provided in the Settings instance.

References

Please see #3358 for details.

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2022-0315

Weaknesses

Credits