Vulnerability CVE-2021-3178: Information

Description

fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to prevent this attack; see also the exports(5) no_subtree_check default behavior

Severity: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Published: Jan. 19, 2021
Modified: May 17, 2024
Error type identifier: CWE-22

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
kernel-image-mpsisyphus5.10.12-alt16.8.8-alt1ALT-PU-2021-1188-1265584Fixed
kernel-image-mpp105.10.12-alt16.1.19-alt1ALT-PU-2021-1188-1265584Fixed
kernel-image-mpp95.10.16-alt15.12.16-alt1ALT-PU-2021-1446-1267460Fixed
kernel-image-rpi-defsisyphus5.10.36-alt15.15.92-alt2ALT-PU-2021-1862-1272154Fixed
kernel-image-rpi-defp105.10.36-alt15.15.92-alt2ALT-PU-2021-1862-1272154Fixed
kernel-image-rpi-defp95.10.36-alt15.10.81-alt1ALT-PU-2021-1866-1272593Fixed
kernel-image-rpi-unsisyphus5.10.17-alt16.6.23-alt1ALT-PU-2021-1417-1266511Fixed
kernel-image-rpi-unp105.10.17-alt16.1.77-alt1ALT-PU-2021-1417-1266511Fixed
kernel-image-rpi-unp95.10.17-alt15.12.17-alt1ALT-PU-2021-1424-1267217Fixed
kernel-image-rtsisyphus5.10.35-alt1.rt396.1.91-alt1.rt31ALT-PU-2021-1870-1272532Fixed
kernel-image-rtp105.10.35-alt1.rt395.10.216-alt1.rt108ALT-PU-2021-1870-1272532Fixed
kernel-image-std-defsisyphus5.10.28-alt16.1.92-alt1ALT-PU-2021-1621-1268839Fixed
kernel-image-std-defp105.10.28-alt15.10.217-alt1ALT-PU-2021-1621-1268839Fixed
kernel-image-std-defc9f25.10.32-alt0.c9f5.10.214-alt0.c9f.2ALT-PU-2021-1739-1270353Fixed
kernel-image-std-kvmsisyphus5.10.29-alt15.10.176-alt1ALT-PU-2021-1656-1269859Fixed
kernel-image-std-kvmp105.10.29-alt15.10.42-alt1ALT-PU-2021-1656-1269859Fixed
kernel-image-un-defsisyphus5.10.9-alt16.6.32-alt1ALT-PU-2021-1089-1264932Fixed
kernel-image-un-defp105.10.9-alt16.1.90-alt1ALT-PU-2021-1089-1264932Fixed
kernel-image-un-defp95.10.9-alt25.10.216-alt2ALT-PU-2021-1127-1264933Fixed
kernel-image-un-defc10f15.10.9-alt16.1.85-alt0.c10f.1ALT-PU-2021-1089-1264932Fixed
kernel-image-un-defc9f25.10.9-alt25.10.29-alt2ALT-PU-2021-1127-1264933Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
      End including
      5.10.8

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*