Database/Control plane, storage & DevOps

Lustre (ptlrpc module): A second out-of-bounds access in ptlrpc triggered by unvalidated client packet fields, ending
Impact
A second out-of-bounds access in ptlrpc triggered by unvalidated client packet fields, ending in a server panic and loss of the shared filesystem for every tenant on it.
Who can reach it
Any host that can speak LNet to a Lustre server. No authentication step stands between a compute node and this code path in a default deployment.
What to do
Upgrade Lustre servers to 2.12.3 or later. Plan an MDS/OSS failover or reboot - Lustre server fixes are kernel-module changes and cannot be hot-applied. DDN EXAScaler ships this Lustre code, so EXAScaler fleets inherit the issue and need DDN's corresponding release rather than an upstream build.
References
Related entries
- Lustre (ptlrpc module): Out-of-bounds read in ptlrpc leading to a server panic. The read primitive also means serverCVE-2019-20428 · Lustre (ptlrpc module)High
- Lustre (ptlrpc module): Out-of-bounds write in the RPC layer, reachable by a client that lies about packet field sizes.CVE-2019-20425 · Lustre (ptlrpc module)High
- Lustre (ptlrpc module, lm_bufcount handling): A client that modifies the lm_bufcount field walks the server off the endCVE-2019-20429 · Lustre (ptlrpc module, lm_bufcount handling)High
- Lustre (mdt module, MDT Body eadatasize): An oversized eadatasize field in an MDT request drives the metadata serverCVE-2019-20430 · Lustre (mdt module, MDT Body eadatasize)High
- Lustre (ptlrpc, osd_map_remote_to_local): Out-of-bounds access in the object-storage mapping path, reachable from aCVE-2019-20431 · Lustre (ptlrpc, osd_map_remote_to_local)High
- Lustre (mdt module): Another unvalidated-field out-of-bounds access in the metadata server, ending in a panic. SameCVE-2019-20432 · Lustre (mdt module)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.