CVE-2020-35513

MEDIUM

Linux Kernel - Denial of Service via NFSv4.2 Umask Handling

Title source: llm
STIX 2.1

Description

A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.

References (2)

Core 2
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1911309

Scores

CVSS v3 4.9
EPSS 0.0032
EPSS Percentile 54.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-271
Status published
Products (2)
linux/linux_kernel 4.2
redhat/enterprise_linux 7.0
Published Jan 26, 2021
Tracked Since Feb 18, 2026