CVE-2020-35513
Summary
| CVE | CVE-2020-35513 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-26 18:15:00 UTC |
| Updated | 2023-11-07 03:21:00 UTC |
| Description | A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service. |
Risk And Classification
Problem Types: CWE-271
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 4.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 4.2 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| nfsd: zero out umask if the client didn't provide one - Patchwork | patchwork.kernel.org | ||
| 1911309 – (CVE-2020-35513) CVE-2020-35513 kernel: Nfsd failure to clear umask after processing an open or create | MISC | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| nfsd: zero out umask if the client didn't provide one - Patchwork | MISC | patchwork.kernel.org | Mailing List, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.