CVE-2021-38202: High severity Linux Linux kernel vulnerability
fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux kernel (fs/nfsd/trace.h / nfsd trace event framework)to a version that resolves this vulnerability.Fixed in 5.13.4
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38202?
CVE-2021-38202 is a denial of service vulnerability in the Linux kernel that allows remote attackers to cause an out-of-bounds read.
How do I fix CVE-2021-38202?
To fix CVE-2021-38202, upgrade the Linux kernel to version 5.13.4 or later.
Which Linux kernel versions are affected by CVE-2021-38202?
CVE-2021-38202 affects Linux kernel versions prior to 5.13.4.
Can CVE-2021-38202 affect NetApp products?
Yes, CVE-2021-38202 can affect NetApp products that use vulnerable versions of the Linux kernel.
What types of attacks can exploit CVE-2021-38202?
Exploiting CVE-2021-38202 can lead to denial of service conditions due to remote NFS traffic abuse.