PT-2020-10444 · Opensuse · Lustre

Published

2020-01-27

·

Updated

2020-01-28

·

CVE-2019-20432

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Lustre file system versions prior to 2.12.3
Description The issue is related to the mdt module in the Lustre file system, where an out-of-bounds access and panic can occur due to the lack of validation for specific fields of packets sent by a client. The mdt file secctx unpack function does not validate the value of name size derived from req capsule get size.
Recommendations For versions prior to 2.12.3, update to version 2.12.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the mdt module to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20432

Affected Products

Lustre