Lustre
Lustre: vulnerabilidades y CVE
Lustre tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-51786 | Crítica (9.1) | 0.50% | — | 7 mar 2024 | An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive information via Incorrect Access Control. |
| CVE-2019-20432 | Alta (7.5) | 1.8% | — | 27 ene 2020 | In the Lustre file system before 2.12.3, the mdt module has an out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. mdt_file_secctx_unpack does not validate the… |
| CVE-2019-20431 | Alta (7.5) | 1.9% | — | 27 ene 2020 | In the Lustre file system before 2.12.3, the ptlrpc module has an osd_map_remote_to_local out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. osd_bufs_get in the… |
| CVE-2019-20430 | Alta (7.5) | 2.2% | — | 27 ene 2020 | In the Lustre file system before 2.12.3, the mdt module has an LBUG panic (via a large MDT Body eadatasize field) due to the lack of validation for specific fields of packets sent by a client. |
| CVE-2019-20429 | Alta (7.5) | 2.2% | — | 27 ene 2020 | In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds read and panic (via a modified lm_bufcount field) due to the lack of validation for specific fields of packets sent by a client. This is… |
| CVE-2019-20428 | Alta (7.5) | 1.8% | — | 27 ene 2020 | In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds read and panic due to the lack of validation for specific fields of packets sent by a client. The ldl_request_cancel function mishandles a… |
| CVE-2019-20427 | Crítica (9.8) | 5.1% | — | 27 ene 2020 | In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic, and possibly remote code execution, due to the lack of validation for specific fields of packets sent by a client. Interaction… |
| CVE-2019-20426 | Alta (7.5) | 1.9% | — | 27 ene 2020 | In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. In the function ldlm_cancel_hpreq_check,… |
| CVE-2019-20425 | Alta (7.5) | 2.2% | — | 27 ene 2020 | In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. In the function lustre_msg_string, there is… |
| CVE-2019-20424 | Alta (7.5) | 2.9% | — | 27 ene 2020 | In the Lustre file system before 2.12.3, mdt_object_remote in the mdt module has a NULL pointer dereference and panic due to the lack of validation for specific fields of packets sent by a client. |
| CVE-2019-20423 | Alta (7.5) | 2.4% | — | 27 ene 2020 | In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic due to the lack of validation for specific fields of packets sent by a client. The function target_handle_connect() mishandles a… |