GPU VulnDB

Database/Control plane, storage & DevOps

Lustre (ptlrpc module): Out-of-bounds read in ptlrpc leading to a server panic. The read primitive also means server

CVE-2019-20428Control plane, storage & DevOpsLU-12603DDN EXAScalercurated

Impact

Out-of-bounds read in ptlrpc leading to a server panic. The read primitive also means server memory adjacent to the RPC buffer can influence behaviour before the crash, so treat it as more than a pure availability bug.

Who can reach it

Any LNet peer - in practice every compute node and every tenant running on one.

What to do

Upgrade Lustre servers to 2.12.3 or later, with an MDS/OSS failover or reboot to load the fixed modules. DDN EXAScaler ships this Lustre code, so EXAScaler fleets inherit the issue and need DDN's corresponding release rather than an upstream build.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.