First published: Sun Aug 08 2021(Updated: )
fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <5.13.4 | |
All of | ||
NetApp Bootstrap OS | ||
NetApp HCI Compute Node | ||
NetApp SolidFire & HCI Management Node | ||
NetApp SolidFire & HCI Storage Node | ||
All of | ||
NetApp Management Services for Element Software | ||
NetApp HCI Storage Nodes | ||
Debian Linux | =9.0 | |
Debian Linux | =11.0 | |
NetApp Bootstrap OS | ||
NetApp HCI Compute Node | ||
NetApp Management Services for Element Software | ||
NetApp HCI Storage Nodes | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.135-1 6.12.22-1 6.12.25-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38199 has a medium severity rating due to its potential to cause denial of service.
To fix CVE-2021-38199, upgrade your Linux kernel to version 5.13.4 or later.
CVE-2021-38199 affects Linux kernel versions prior to 5.13.4, including Debian Linux 9.0 and 11.0.
CVE-2021-38199 could be exploited by operators of remote NFSv4 servers to induce denial of service by making mounts unreachable.
Yes, a patch for CVE-2021-38199 is included in the updates for the Linux kernel from version 5.13.4 onward.