VDB
CVE-2019-20429
CVE-2019-20429
PUBLISHED
In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds read and panic (via a modified lm_bufcount field) due to the lack of validation for specific fields of packets sent by a client. This is caused by interaction between sptlrpc_svc_unwrap_request and lustre_msg_hdr_size_v2.
EPSS 0.66% · 71.5th percentile
Risk Scores
EPSS Score
0.66%
71.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:FIPS:18.04:LTS | linux-gcp-fips | 4.15.0-1001.1, 0 |
| Ubuntu:18.04:LTS | linux-gcp-edge | *, *, 0 |
| Ubuntu:Pro:18.04:LTS | linux | 4.15.0-197.208, 4.15.0-200.211, 4.15.0-201.212 |
| Ubuntu:Pro:16.04:LTS | linux-gcp | 4.15.0-1112.126~16.04.1, 4.15.0-1116.130~16.04.1, * |
| Ubuntu:Pro:FIPS:18.04:LTS | linux-fips | 4.15.0-1011.12, 0 |
| Ubuntu:Pro:FIPS-updates:18.04:LTS | linux-azure-fips | 4.15.0-2008.9, 4.15.0-2018.21, 4.15.0-2086.92 |
| Ubuntu:Pro:18.04:LTS | linux-azure-4.15 | 4.15.0-1149.164, 0, 4.15.0-1083.93 |
| Ubuntu:Pro:18.04:LTS | linux-kvm | 4.15.0-1002.2, 4.15.0-1008.8, 4.15.0-1038.38 |
| Ubuntu:Pro:FIPS:18.04:LTS | linux-azure-fips | 4.15.0-1002.2, 0 |
| Ubuntu:Pro:16.04:LTS | linux-kvm | 4.4.0-1008.13, 4.4.0-1021.26, 4.4.0-1033.39 |
| Ubuntu:Pro:14.04:LTS | linux-lts-xenial | 4.4.0-277.311~14.04.1, 4.4.0-13.29~14.04.1, 4.4.0-14.30~14.04.2 |
| Ubuntu:24.04:LTS | linux-raspi-realtime | 0, 6.8.0-2019.20 |
| Ubuntu:Pro:16.04:LTS | linux-aws | 4.4.0-1012.21, 4.4.0-1011.20, 4.4.0-1009.18 |
| Ubuntu:Pro:14.04:LTS | linux | 3.13.0-174.225, 3.13.0-183.234, 3.13.0-182.233 |
| Ubuntu:Pro:FIPS-updates:18.04:LTS | linux-aws-fips | 4.15.0-2069.72, 4.15.0-2033.34, 4.15.0-2034.35 |
| Ubuntu:Pro:FIPS:18.04:LTS | linux-aws-fips | 4.15.0-2000.4, 0 |
| Ubuntu:18.04:LTS | linux-oem | 4.15.0-1035.40, 4.15.0-1036.41, 4.15.0-1038.43 |
| Ubuntu:Pro:14.04:LTS | linux-azure | 4.15.0-1031.32~14.04.1, 0, 4.15.0-1023.24~14.04.1 |
| Ubuntu:18.04:LTS | linux-aws-5.0 | 5.0.0-1025.28, 0, 5.0.0-1021.24~18.04.1 |
| Ubuntu:Pro:16.04:LTS | linux-oracle | *, 4.15.0-1035.38~16.04.1, 4.15.0-1037.41~16.04.1 |
…and 16 more
Exploit Intelligence
Timeline
- Jan 27, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-20429 third-party-advisory
- http://lustre.org/ third-party-advisory
- http://wiki.lustre.org/Lustre_2.12.3_Changelog third-party-advisory
- https://jira.whamcloud.com/browse/LU-12590 third-party-advisory
- https://review.whamcloud.com/#/c/36119/ third-party-advisory
- https://git.whamcloud.com/?p=fs/lustre-release.git;a=commitdiff;h=268edb13d769994c4841864034d72f0bd7b36e12 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-20429 third-party-advisory