PT-2021-2999 · Linux+3 · Linux Kernel+3

吴异

·

Published

2021-01-12

·

Updated

2024-08-03

·

CVE-2021-3178

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.10.8
Description The issue is related to the fs/nfsd/nfs3xdr.c component in the Linux kernel, which allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS when there is an NFS export of a subdirectory of a filesystem. Some parties argue that such a subdirectory export is not intended to prevent this attack, and it is also related to the exports(5) no subtree check default behavior.
Recommendations For Linux kernel versions through 5.10.8, consider disabling the READDIRPLUS functionality as a temporary workaround until a patch is available. Restrict access to the vulnerable fs/nfsd/nfs3xdr.c component to minimize the risk of exploitation. Avoid using the NFS export of a subdirectory of a filesystem until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1089
ALT-PU-2021-1127
ALT-PU-2021-1188
ALT-PU-2021-1211
ALT-PU-2021-1417
ALT-PU-2021-1424
ALT-PU-2021-1446
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
BDU:2021-02592
BDU:2021-02593
CVE-2021-3178
DLA-2586-1
MGASA-2021-0058
MGASA-2021-0061
OESA-2021-1086
OESA-2021-1087
USN-4876-1
USN-4877-1
USN-4878-1
USN-4910-1
USN-4912-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Ubuntu