CVE-2019-20428 is an out-of-bounds read vulnerability affecting the Lustre file system before version 2.12.3, specifically within the ptlrpc module. This flaw arises from insufficient validation of client-sent packet fields, leading to a system panic when the ldl_request_cancel function mishandles a large lock_count parameter. With a CVSS score of 7.5 (HIGH), this vulnerability can be exploited remotely without authentication and results in a denial of service. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.12.3CPE matchmatch criteria | cpe:2.3:a:lustre:lustre:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.