First published: Wed Jan 27 2021(Updated: )
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cifs-utils | <6.13 | 6.13 |
Samba Cifs-utils | >=4.0<6.13 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this flaw is CVE-2021-20208.
The severity of CVE-2021-20208 is medium with a severity value of 6.1.
Versions of cifs-utils before 6.13 are affected by this vulnerability.
To fix this vulnerability, update cifs-utils to version 6.13 or later.
The highest threat from CVE-2021-20208 is to data confidentiality and integrity.