Database/Control plane, storage & DevOps

Lustre (mdt module): Another unvalidated-field out-of-bounds access in the metadata server, ending in a panic. Same
Impact
Another unvalidated-field out-of-bounds access in the metadata server, ending in a panic. Same blast radius as the rest of the 2.12.3 batch - the shared namespace goes away for every tenant at once.
Who can reach it
Any Lustre client with LNet reachability to the MDS.
What to do
Upgrade Lustre servers to 2.12.3 or later. Treat the whole CVE-2019-20423 through CVE-2019-20432 family as one upgrade - they were all fixed in the same release and patching only the ones you have heard of leaves the rest live. DDN EXAScaler ships this Lustre code, so EXAScaler fleets inherit the issue and need DDN's corresponding release rather than an upstream build.
References
Related entries
- NetApp Clustered Data ONTAP (unauthenticated information disclosure): An attacker with no account extracts sensitiveCVE-2019-5491 · NetApp Clustered Data ONTAP (unauthenticated information disclosure)High
- ntpd (NTP.org reference implementation): An off-path attacker can block a node's unauthenticated time synchronizationCVE-2020-11868 · ntpd (NTP.org reference implementation)High
- Ceph RADOS Gateway (RGW): A POST carrying malformed object-tagging XML dereferences a NULL pointer and kills theCVE-2020-12059 · Ceph RADOS Gateway (RGW)High
- Ceph dashboard (ceph-mgr dashboard module): An unauthenticated HTTP request with traversal sequences reads arbitraryCVE-2020-1699 · Ceph dashboard (ceph-mgr dashboard module)High
- IBM Elastic Storage System / Elastic Storage Server (UDP request handling): An unauthenticated attacker who can sendCVE-2020-5015 · IBM Elastic Storage System / Elastic Storage Server (UDP request handling)High
- NetApp Clustered Data ONTAP httpd: A remote attacker with no credentials crashes the ONTAP web server, removingCVE-2021-27005 · NetApp Clustered Data ONTAP httpdHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.