PT-2021-4121 · Linux+8 · Linux Kernel+8

Published

2021-06-13

·

Updated

2024-04-23

·

CVE-2021-38201

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.13.4
Description The issue is related to the xdr set page base function in the net/sunrpc/xdr.c file of the Linux kernel. It allows remote attackers to cause a denial of service by performing many NFS 4.2 READ PLUS operations, resulting in a slab-out-of-bounds access.
Recommendations For Linux kernel versions prior to 5.13.4, update to version 5.13.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of NFS 4.2 READ PLUS operations until a patch is applied.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:3447
ALT-PU-2021-2284
ALT-PU-2021-2486
ALT-PU-2021-2616
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
AZL-6585
BDU:2021-04711
CESA-2021_3440
CESA-2021_3447
CVE-2021-38201
RHSA-2021:3440
RHSA-2021:3447
RHSA-2021_3440
RHSA-2021_3447
RLSA-2021:3440
RLSA-2021:3447
USN-5092-1
USN-5092-2
USN-5092-3
USN-5096-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Ubuntu