Database/Control plane, storage & DevOps

Lustre (mdt module, MDT Body eadatasize): An oversized eadatasize field in an MDT request drives the metadata server
Impact
An oversized eadatasize field in an MDT request drives the metadata server into an LBUG panic. The MDS is the single point every file open goes through, so this is a full namespace outage for all tenants.
Who can reach it
Any Lustre client able to send MDT requests, i.e. any node with the filesystem mounted.
What to do
Upgrade Lustre to 2.12.3 or later on the metadata servers. Requires an MDS failover or reboot. If you run an active/passive MDS pair, patch the passive side first and fail over rather than taking a cold outage. DDN EXAScaler ships this Lustre code, so EXAScaler fleets inherit the issue and need DDN's corresponding release rather than an upstream build.
References
Related entries
- Lustre (ptlrpc, osd_map_remote_to_local): Out-of-bounds access in the object-storage mapping path, reachable from aCVE-2019-20431 · Lustre (ptlrpc, osd_map_remote_to_local)High
- Lustre (mdt module): Another unvalidated-field out-of-bounds access in the metadata server, ending in a panic. SameCVE-2019-20432 · Lustre (mdt module)High
- NetApp Clustered Data ONTAP (unauthenticated information disclosure): An attacker with no account extracts sensitiveCVE-2019-5491 · NetApp Clustered Data ONTAP (unauthenticated information disclosure)High
- ntpd (NTP.org reference implementation): An off-path attacker can block a node's unauthenticated time synchronizationCVE-2020-11868 · ntpd (NTP.org reference implementation)High
- Ceph RADOS Gateway (RGW): A POST carrying malformed object-tagging XML dereferences a NULL pointer and kills theCVE-2020-12059 · Ceph RADOS Gateway (RGW)High
- Ceph dashboard (ceph-mgr dashboard module): An unauthenticated HTTP request with traversal sequences reads arbitraryCVE-2020-1699 · Ceph dashboard (ceph-mgr dashboard module)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.