GPU VulnDB

Database/Control plane, storage & DevOps

Lustre (ptlrpc module, lm_bufcount handling): A client that modifies the lm_bufcount field walks the server off the end

CVE-2019-20429Control plane, storage & DevOpsLU-12590DDN EXAScalercurated

Impact

A client that modifies the lm_bufcount field walks the server off the end of a buffer and panics it. One line of client-side code takes down storage for the whole cluster.

Who can reach it

Any Lustre client on the fabric. Trivial to trigger once you know the field - no privileged position needed beyond mounting the filesystem.

What to do

Upgrade Lustre servers to 2.12.3 or later and fail over or reboot the affected servers to load the new modules. DDN EXAScaler ships this Lustre code, so EXAScaler fleets inherit the issue and need DDN's corresponding release rather than an upstream build.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.