Volcano
v1.15.2Orchestration & ManagementAug 29, 2026
A security-focused maintenance release fixes a scheduler denial-of-service vulnerability in Dynamic Resource Allocation. It also contains corrections for scheduling and workload-management defects.
Check if affected (1)
securityGHSA-j38h-7pfq-cxmw scheduler denial-of-service vulnerability
Applies if you use
Dynamic Resource Allocation.A vulnerability in Volcano's
Dynamic Resource Allocationcapacity accounting could let an authenticated tenant exhaust scheduler CPU time with tenant-controlled device or task counts. The fix uses constant-time capacity aggregation with safer validation and overflow handling.
All 4 other recorded changesfixes 4
fixes (4)
- * [release-1.15] Prevent a nil-pointer panic in backfill when node scoring fails to select a best node by @mesutoezdil in #5916
- * [release-1.15] Recheck predicate and device feasibility after tentative reclaim evictions, allowing reclaim to continue until a concrete device allocation is possible by @miantalha45 in #5898
- * [release-1.15] Fix HAMi Ascend normal preemption when evicting lower-priority workloads makes sufficient device capacity available by @miantalha45 in #5866
- * [release-1.15] Keep PodGroups Running while scheduled member Pods are gracefully terminating and avoid misleading
NotEnoughResourcesconditions by @halcyon-r in #5840
Add Volcano to your stack
A weekly email arrives when a release needs action. Like the security patches in this release.