Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-35513

Опубликовано: 21 дек. 2020
Источник: redhat
CVSS3: 4.4

Описание

A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.

Отчет

This flaw is rated as having Low impact because of the exploitation prerequisities and the fact that the attacker could only decrease the permissions of the file or directory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernel-altAffected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2021:033802.02.2021
Red Hat Enterprise Linux 7kernelFixedRHSA-2021:033602.02.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-271
https://bugzilla.redhat.com/show_bug.cgi?id=1911309kernel: Nfsd failure to clear umask after processing an open or create

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 4 лет назад

A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.

CVSS3: 4.9
nvd
больше 4 лет назад

A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.

CVSS3: 4.9
debian
больше 4 лет назад

A flaw incorrect umask during file or directory modification in the Li ...

github
около 3 лет назад

A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.

oracle-oval
больше 4 лет назад

ELSA-2021-0336: kernel security, bug fix, and enhancement update (MODERATE)

4.4 Medium

CVSS3