The OpenHPC community is pleased to announce the release of version 3.6. This is a minimal, security-focused release that updates Slurm and Lmod to address recently disclosed CVEs, and is recommended for all OpenHPC 3.x deployments.
Key Highlights in OpenHPC v3.6
Slurm Security Update: Slurm has been updated to 25.11.8, resolving eight CVEs disclosed by SchedMD: CVE-2026-65107, CVE-2026-65108, CVE-2026-65109, CVE-2026-65138, CVE-2026-65139, CVE-2026-65140, CVE-2026-65165, and CVE-2026-65168. These include fixes for credential-verification bypasses, a slurmstepd stack overflow, an OCI container cleanup path-traversal issue, a heap over-read in slurmd, and a privilege-escalation path through the accounting database. Sites running slurmdbd should update that component first. See the Slurm 25.11.8 changelog for full details.
Lmod Security Update: Lmod has been updated to 9.4, fixing CVE-2026-85013, a command-injection issue in bash tab-completion for module/ml that could expand command substitution in module names, collection names, or MODULEPATH entries. The issue was found by AISLE in partnership with Red Hat.
NHC Performance Fix: node-health-check (NHC) includes a cherry-picked upstream fix that speeds up /proc/cpuinfo parsing, avoiding timeouts (and nodes being marked down in Slurm) on systems with large CPU counts. This is a performance fix, not a security update.
Getting Started
- Release Details: OpenHPC v3.6 Release Notes
- Installation Guide: OpenHPC 3.x Wiki
- Downloads: RPM packages are available through the OpenHPC repositories
Register Your OpenHPC System
If you are using OpenHPC, please consider registering your system. Registration data helps the community understand deployment patterns and prioritize future development efforts.