Database/Control plane, storage & DevOps

Lustre (ptlrpc, osd_map_remote_to_local): Out-of-bounds access in the object-storage mapping path, reachable from a
CVE-2019-20431Control plane, storage & DevOpsLU-12612DDN EXAScalercurated
Impact
Out-of-bounds access in the object-storage mapping path, reachable from a crafted client packet, ending in a panic on the object storage server. Loses the OSTs behind it, which is where the training data and checkpoints live.
Who can reach it
Any Lustre client on the LNet fabric.
What to do
Upgrade Lustre servers to 2.12.3 or later; fail over or reboot the OSS nodes to load the fixed modules. DDN EXAScaler ships this Lustre code, so EXAScaler fleets inherit the issue and need DDN's corresponding release rather than an upstream build.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.