{
    "id": "CVE-2019-20427",
    "published": "2020-01-27 05:15:12",
    "last_modified": "2026-06-17 02:30:24",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-120",
    "description": "In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic, and possibly remote code execution, due to the lack of validation for specific fields of packets sent by a client. Interaction between req_capsule_get_size and tgt_brw_write leads to a tgt_shortio2pages integer signedness error.",
    "epss_score": "0.05099",
    "epss_percentile": "0.92139",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-07 18:17:20",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "lustre",
            "product": "lustre"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://lustre.org/",
        "http://wiki.lustre.org/Lustre_2.12.3_Changelog",
        "https://jira.whamcloud.com/browse/LU-12600",
        "https://review.whamcloud.com/#/c/35867/",
        "http://lustre.org/",
        "http://wiki.lustre.org/Lustre_2.12.3_Changelog",
        "https://jira.whamcloud.com/browse/LU-12600",
        "https://review.whamcloud.com/#/c/35867/"
    ]
}