GPU VulnDB

Database/Control plane, storage & DevOps

Lustre (ptlrpc module): A second out-of-bounds access in ptlrpc triggered by unvalidated client packet fields, ending

CVE-2019-20426Control plane, storage & DevOpsLU-12614DDN EXAScalercurated

Impact

A second out-of-bounds access in ptlrpc triggered by unvalidated client packet fields, ending in a server panic and loss of the shared filesystem for every tenant on it.

Who can reach it

Any host that can speak LNet to a Lustre server. No authentication step stands between a compute node and this code path in a default deployment.

What to do

Upgrade Lustre servers to 2.12.3 or later. Plan an MDS/OSS failover or reboot - Lustre server fixes are kernel-module changes and cannot be hot-applied. DDN EXAScaler ships this Lustre code, so EXAScaler fleets inherit the issue and need DDN's corresponding release rather than an upstream build.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.