Database/Control plane, storage & DevOps

Lustre (ptlrpc module, lm_bufcount handling): A client that modifies the lm_bufcount field walks the server off the end
Impact
A client that modifies the lm_bufcount field walks the server off the end of a buffer and panics it. One line of client-side code takes down storage for the whole cluster.
Who can reach it
Any Lustre client on the fabric. Trivial to trigger once you know the field - no privileged position needed beyond mounting the filesystem.
What to do
Upgrade Lustre servers to 2.12.3 or later and fail over or reboot the affected servers to load the new modules. DDN EXAScaler ships this Lustre code, so EXAScaler fleets inherit the issue and need DDN's corresponding release rather than an upstream build.
References
Related entries
- Lustre (mdt module, MDT Body eadatasize): An oversized eadatasize field in an MDT request drives the metadata serverCVE-2019-20430 · Lustre (mdt module, MDT Body eadatasize)High
- Lustre (ptlrpc, osd_map_remote_to_local): Out-of-bounds access in the object-storage mapping path, reachable from aCVE-2019-20431 · Lustre (ptlrpc, osd_map_remote_to_local)High
- Lustre (mdt module): Another unvalidated-field out-of-bounds access in the metadata server, ending in a panic. SameCVE-2019-20432 · Lustre (mdt module)High
- NetApp Clustered Data ONTAP (unauthenticated information disclosure): An attacker with no account extracts sensitiveCVE-2019-5491 · NetApp Clustered Data ONTAP (unauthenticated information disclosure)High
- ntpd (NTP.org reference implementation): An off-path attacker can block a node's unauthenticated time synchronizationCVE-2020-11868 · ntpd (NTP.org reference implementation)High
- Ceph RADOS Gateway (RGW): A POST carrying malformed object-tagging XML dereferences a NULL pointer and kills theCVE-2020-12059 · Ceph RADOS Gateway (RGW)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.