There's a CVE (from 9/9) against pmix and all versions in RHEL/CentOS Stream seem to be affected https://nvd.nist.gov/vuln/detail/CVE-2023-41915 OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0. Base score: 8.1 (high) Please provide the package NVR for which bug is seen: c8s has pmix-2.2.5-1.el8 c9s has pmix-3.2.3-3.el9 Fedora (rawhide) has 4.1.2-5.fc39 - https://src.fedoraproject.org/rpms/pmix There's a WIP PR for 4.2.4rc1 that we can probably use as a base to fix this https://src.fedoraproject.org/rpms/pmix/pull-request/4 Note: github.com/pmix/pmix now redirects to github.com/openpmix/openpmix, so while we list the old URL in our sources this is very likely affecting our packages. Reproducible: Always
Upstream cut a final 4.1.x point release backporting the fix, so this is probably the one we should deploy on all versions before then moving Rawhide to 4.2.x or 5.x: https://src.fedoraproject.org/rpms/pmix/pull-request/5
*** This bug has been marked as a duplicate of bug 2239124 ***