VDB

CVE-2019-20427

CVE-2019-20427 PUBLISHED

In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic, and possibly remote code execution, due to the lack of validation for specific fields of packets sent by a client. Interaction between req_capsule_get_size and tgt_brw_write leads to a tgt_shortio2pages integer signedness error.

EPSS 3.70% · 88.2th percentile

Risk Scores

EPSS Score
3.70%
88.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-gcp-edge4.18.0-1006.7~18.04.1, 4.18.0-1008.9~18.04.1, 4.18.0-1009.10~18.04.1
Ubuntu:18.04:LTSlinux-azure-edge0, 4.18.0-1006.6~18.04.1, 4.18.0-1007.7~18.04.1
Ubuntu:16.04:LTSlinux-hwe-edge*, *, 4.15.0-23.25~16.04.1
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-108.131~14.04.1, 4.4.0-112.135~14.04.1, 4.4.0-119.143~14.04.1
Ubuntu:Pro:14.04:LTSlinux3.13.0-5.20, 0, 3.11.0-12.19
Ubuntu:Pro:14.04:LTSlinux-azure*, *, *
Ubuntu:18.04:LTSlinux-hwe-edge5.3.0-24.26~18.04.2, *, *
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1142.148, 4.4.0-1145.151, 4.4.0-1146.152

Timeline

  • Jan 27, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›