CVE-2020-35513
published 2021-01-26CVE-2020-35513: A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and…
PriorityP424medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
1.35%
68.6th percentile
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.16.5-1 (bookworm) | linux 4.16.5-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7qpq-c35p-wc3c: A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user cre
ghsa_unreviewed·2022-05-24
CVE-2020-35513 [MEDIUM] CWE-271 GHSA-7qpq-c35p-wc3c: A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user cre
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.
OSV
CVE-2020-35513: A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user cre
osv·2021-01-26·CVSS 4.9
CVE-2020-35513 [MEDIUM] CVE-2020-35513: A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user cre
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.
Red Hat
kernel: Nfsd failure to clear umask after processing an open or create
vendor_redhat·2020-12-21·CVSS 4.9
CVE-2020-35513 [MEDIUM] CWE-271 kernel: Nfsd failure to clear umask after processing an open or create
kernel: Nfsd failure to clear umask after processing an open or create
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw
Debian
CVE-2020-35513: linux - A flaw incorrect umask during file or directory modification in the Linux kernel...
vendor_debian·2020·CVSS 4.9
CVE-2020-35513 [MEDIUM] CVE-2020-35513: linux - A flaw incorrect umask during file or directory modification in the Linux kernel...
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.
Scope: local
bookworm: resolved (fixed in 4.16.5-1)
bullseye: resolved (fixed in 4.16.5-1)
forky: resolved (fixed in 4.16.5-1)
sid: resolved (fixed in 4.16.5-1)
trixie: resolved (fixed in 4.16.5-1)
No detection rules found.
No public exploits indexed.
2021-01-26
Published