7.8

CVE-2021-47107

Exploit

NFSD: Fix READDIR buffer overflow

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Fix READDIR buffer overflow

If a client sends a READDIR count argument that is too small (say,
zero), then the buffer size calculation in the new init_dirlist
helper functions results in an underflow, allowing the XDR stream
functions to write beyond the actual buffer.

This calculation has always been suspect. NFSD has never sanity-
checked the READDIR count argument, but the old entry encoders
managed the problem correctly.

With the commits below, entry encoding changed, exposing the
underflow to the pointer arithmetic in xdr_reserve_space().

Modern NFS clients attempt to retrieve as much data as possible
for each READDIR request. Also, we have no unit tests that
exercise the behavior of READDIR at the lower bound of @count
values. Thus this case was missed during testing.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.13 < 5.15.12
Linux ≫ Linux Kernel Version 5.16 Update rc1
Linux ≫ Linux Kernel Version 5.16 Update rc2
Linux ≫ Linux Kernel Version 5.16 Update rc3
Linux ≫ Linux Kernel Version 5.16 Update rc4
Linux ≫ Linux Kernel Version 5.16 Update rc5
Linux ≫ Linux Kernel Version 5.16 Update rc6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.85% 0.545
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

https://git.kernel.org/stable/c/53b1119a6e5028b125f431a0116ba73510d82a72
Patch
Exploit
Mailing List
https://git.kernel.org/stable/c/9e291a6a28d32545ed2fd959a8165144d1724df1
Patch
Exploit
Mailing List
https://git.kernel.org/stable/c/eabc0aab98e5218ceecd82069b0d6fdfff5ee885
Patch
Exploit
Mailing List
https://cert-portal.siemens.com/productcert/html/ssa-265688.html