The OpenHPC community is pleased to announce the release of version 2.11. This release updates Slurm and Lmod to address recently disclosed CVEs, and also includes an EasyBuild upgrade. It is recommended for all OpenHPC 2.x deployments.
Key Highlights in OpenHPC v2.11
Slurm Security Update: Slurm has been updated to 25.05.9, resolving eight CVEs disclosed by SchedMD: CVE-2026-65107, CVE-2026-65108, CVE-2026-65109, CVE-2026-65138, CVE-2026-65139, CVE-2026-65140, CVE-2026-65165, and CVE-2026-65168. These include fixes for credential-verification bypasses, a slurmstepd stack overflow, an OCI container cleanup path-traversal issue, a heap over-read in slurmd, and a privilege-escalation path through the accounting database. Sites running slurmdbd should update that component first. See the Slurm 25.05.9 changelog for full details.
Lmod Security Update: Lmod has been updated to 9.4.2, fixing CVE-2026-85013, a command-injection issue in bash tab-completion for module/ml that could expand command substitution in module names, collection names, or MODULEPATH entries. The issue was found by AISLE in partnership with Red Hat.
EasyBuild Update: EasyBuild has been updated to v5.4.0. This is a regular feature/maintenance update and does not address any security issue.
Getting Started
- Release Details: OpenHPC v2.11 Release Notes
- Installation Guide: OpenHPC 2.x Wiki
- Downloads: RPM packages are available through the OpenHPC repositories
Register Your OpenHPC System
If you are using OpenHPC, please consider registering your system. Registration data helps the community understand deployment patterns and prioritize future development efforts.