Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic due to the lack of validation for specific fields of packets sent by a client. The function target_handle_connect() mishandles a certain size value when a client connects to a server, because of an integer signedness error.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lustre ptlrpc模块缓冲区错误漏洞
Vulnerability Description
Lustre是Lustre社区的一款为大规模计算系统提供一个全局一致的与POSIX兼容的分布式并行文件系统。 Lustre 2.12.3之前版本中的ptlrpc模块的‘target_handle_connect’函数存在缓冲区错误漏洞。远程攻击者可借助特制数据包利用该漏洞导致系统崩溃。
CVSS Information
N/A
Vulnerability Type
N/A