CVE-2019-20430: Lustre
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
In the Lustre file system before 2.12.3, the mdt module has an LBUG panic (via a large MDT Body eadatasize field) due to the lack of validation for specific fields of packets sent by a client.
Affected products
- Lustre Lustre: before 2.12.3 (fixed in 2.12.3)
Published 2020-01-27. Last modified 2026-06-17.