Aggregates CVE and security vulnerability intelligence across all lustre-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk memory corruption and vendor risk buffer overflow and related problems; some flaws may lead to vendor impact memory corruption, affecting vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2019-20432 | In the Lustre file system before 2.12.3, the mdt module has an out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. mdt_file_secctx_unpack does not validate the value of name_size derived from req_capsule_get_size. | [email protected] | 7.5 | 0.61% | 2020-01-27 | 2024-11-21 |
| CVE-2019-20431 | In the Lustre file system before 2.12.3, the ptlrpc module has an osd_map_remote_to_local out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. osd_bufs_get in the osd_ldiskfs module does not validate a certain length value. | [email protected] | 7.5 | 0.66% | 2020-01-27 | 2024-11-21 |
| CVE-2019-20430 | In the Lustre file system before 2.12.3, the mdt module has an LBUG panic (via a large MDT Body eadatasize field) due to the lack of validation for specific fields of packets sent by a client. | [email protected] | 7.5 | 0.66% | 2020-01-27 | 2024-11-21 |
| CVE-2019-20429 | In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds read and panic (via a modified lm_bufcount field) due to the lack of validation for specific fields of packets sent by a client. This is caused by interaction between sptlrpc_svc_unwrap_request and lustre_msg_hdr_size_v2. | [email protected] | 7.5 | 0.66% | 2020-01-27 | 2024-11-21 |
| CVE-2019-20428 | In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds read and panic due to the lack of validation for specific fields of packets sent by a client. The ldl_request_cancel function mishandles a large lock_count parameter. | [email protected] | 7.5 | 0.66% | 2020-01-27 | 2024-11-21 |
| CVE-2019-20427 | In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic, and possibly remote code execution, due to the lack of validation for specific fields of packets sent by a client. Interaction between req_capsule_get_size and tgt_brw_write leads to a tgt_shortio2pages integer signedness error. | [email protected] | 9.8 | 3.70% | 2020-01-27 | 2024-11-21 |
| CVE-2019-20426 | In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. In the function ldlm_cancel_hpreq_check, there is no lock_count bounds check. | [email protected] | 7.5 | 0.66% | 2020-01-27 | 2024-11-21 |
| CVE-2019-20425 | In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. In the function lustre_msg_string, there is no validation of a certain length value derived from lustre_msg_buflen_v2. | [email protected] | 7.5 | 0.66% | 2020-01-27 | 2024-11-21 |
| CVE-2019-20424 | In the Lustre file system before 2.12.3, mdt_object_remote in the mdt module has a NULL pointer dereference and panic due to the lack of validation for specific fields of packets sent by a client. | [email protected] | 7.5 | 0.67% | 2020-01-27 | 2024-11-21 |
| CVE-2019-20423 | In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic due to the lack of validation for specific fields of packets sent by a client. The function target_handle_connect() mishandles a certain size value when a client connects to a server, because of an integer signedness error. | [email protected] | 7.5 | 0.62% | 2020-01-27 | 2024-11-21 |
| CVE-2008-4970 | runiozone in lustre 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/iozone.log temporary file. | [email protected] | 6.9 | 0.04% | 2008-11-06 | 2026-04-23 |