Database/Control plane, storage & DevOps
ntpd (protocol engine, zero-origin timestamp): Continually sending packets with a zero-origin timestamp lets a remote
Impact
Continually sending packets with a zero-origin timestamp lets a remote attacker disrupt an ntpd peer association. Cheap, stateless, and it needs nothing but the ability to send UDP to port 123 — which is open on far more cluster nodes than operators realise, because NTP is usually configured once at image-build time and never reviewed.
Who can reach it
Remote, unauthenticated — UDP packets to the NTP port.
What to do
Upgrade ntp to 4.2.8p11 or later and restart. Also firewall UDP/123 so only your internal time servers can reach cluster nodes — a host or fabric ACL change, applied live, that removes most of the NTP attack surface at once.
References
Related entries
- Ceph RADOS Gateway (RGW, Beast frontend): An unauthenticated client can crash radosgw by sending valid headers followedCVE-2019-10222 · Ceph RADOS Gateway (RGW, Beast frontend)High
- Slurm (srun --uid): Srun --uid drops privileges in the wrong order, so a step launched through it can end up runningCVE-2019-19728 · Slurm (srun --uid)High
- Lustre ptlrpc / mdt modules (client-driven server panic family): The head of a family of ten Lustre defectsCVE-2019-20423 · Lustre ptlrpc / mdt modules (client-driven server panic family)High
- Lustre (mdt module, mdt_object_remote): A client sends a packet with unvalidated fields and the metadata serverCVE-2019-20424 · Lustre (mdt module, mdt_object_remote)High
- Lustre (ptlrpc module): Out-of-bounds write in the RPC layer, reachable by a client that lies about packet field sizes.CVE-2019-20425 · Lustre (ptlrpc module)High
- Lustre (ptlrpc module): A second out-of-bounds access in ptlrpc triggered by unvalidated client packet fields, endingCVE-2019-20426 · Lustre (ptlrpc module)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.