CVE-2021-38201: Buffer Overflow
A flaw was found in the Linux kernel that allows remote attackers to cause a denial of service (xdrsetpagebase slab-out-of-bounds access) by performing many NFS 4.2 READPLUS operations. The highest threat from this vulnerability is to system availability.
Other sources
net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdrsetpagebase slab-out-of-bounds access) by performing many NFS 4.2 READPLUS operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.17.1.rt7.89.el8_4 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.17.1.el8_4 - Upgrade
Upgrade
redhat/Linux kernelto a version that resolves this vulnerability.Fixed in 5.14 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux kernel (net/sunrpc/xdr.c)to a version that resolves this vulnerability.Fixed in 5.13.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-38201?
CVE-2021-38201 has a high severity as it can lead to a denial of service and affect system availability.
How do I fix CVE-2021-38201?
To fix CVE-2021-38201, upgrade to kernel version 0:4.18.0-305.17.1.rt7.89.el8_4 or higher, or apply the relevant patches provided by your distribution.
Which versions are affected by CVE-2021-38201?
CVE-2021-38201 affects Linux kernel versions between 5.11.0 and 5.13.4, along with specific versions of Red Hat and Debian kernels.
Can I mitigate CVE-2021-38201 without patching?
Mitigation for CVE-2021-38201 may be limited, but best practices include limiting NFS operations or applying firewall rules to restrict access.
Is CVE-2021-38201 related to NFS operations?
Yes, CVE-2021-38201 is specifically related to multiple NFS 4.2 READ_PLUS operations triggering a denial of service vulnerability.