CVE-2020-35513
MEDIUMLinux Kernel - Denial of Service via NFSv4.2 Umask Handling
Title source: llmDescription
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.
References (2)
Core 2
Core References
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1911309
Various Sources x_refsource_misc
https://patchwork.kernel.org/project/linux-nfs/patch/20180403203916.GH20297%40fieldses.org/
Scores
CVSS v3
4.9
EPSS
0.0032
EPSS Percentile
54.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-271
Status
published
Products (2)
linux/linux_kernel
4.2
redhat/enterprise_linux
7.0
Published
Jan 26, 2021
Tracked Since
Feb 18, 2026