← Zuruck zu CVEs
CVE-2020-35513
MEDIUM4.9
Beschreibung
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.
CVE Details
CVSS v3.1 Bewertung4.9
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienHIGH
BenutzerinteraktionNONE
Veroffentlicht1/26/2021
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
linux:linux_kernelredhat:enterprise_linux
Schwachen (CWE)
CWE-271
Referenzen
https://bugzilla.redhat.com/show_bug.cgi?id=1911309(secalert@redhat.com)
https://patchwork.kernel.org/project/linux-nfs/patch/20180403203916.GH20297%40fieldses.org/(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=1911309(af854a3a-2127-422b-91ae-364da2661108)
https://patchwork.kernel.org/project/linux-nfs/patch/20180403203916.GH20297%40fieldses.org/(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.