CVE-2021-38199: Medium severity Linux Linux kernel vulnerability
fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux kernel fs/nfs/nfs4client.cto a version that resolves this vulnerability.Fixed in 5.13.4
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38199?
CVE-2021-38199 has a medium severity rating due to its potential to cause denial of service.
How do I fix CVE-2021-38199?
To fix CVE-2021-38199, upgrade your Linux kernel to version 5.13.4 or later.
Which systems are affected by CVE-2021-38199?
CVE-2021-38199 affects Linux kernel versions prior to 5.13.4, including Debian Linux 9.0 and 11.0.
What types of attacks could exploit CVE-2021-38199?
CVE-2021-38199 could be exploited by operators of remote NFSv4 servers to induce denial of service by making mounts unreachable.
Is there a patch available for CVE-2021-38199?
Yes, a patch for CVE-2021-38199 is included in the updates for the Linux kernel from version 5.13.4 onward.