
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-38201 affects the Linux kernel versions before 5.13.4, specifically in the net/sunrpc/xdr.c component. The vulnerability was discovered and disclosed in August 2021. The issue allows remote attackers to cause a denial of service through xdrsetpagebase slab-out-of-bounds access by performing many NFS 4.2 READPLUS operations (NVD, MITRE CVE).
The vulnerability exists in the net/sunrpc/xdr.c file of the Linux kernel where an out-of-bounds access can occur in the xdrsetpage_base function. The issue has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating it is network accessible, requires low attack complexity, and can result in high availability impact (NVD).
When successfully exploited, this vulnerability can lead to a denial of service condition in affected systems. The attack can be triggered remotely through NFS 4.2 READ_PLUS operations, potentially causing system crashes or service disruptions (NetApp Advisory).
The vulnerability was fixed in Linux kernel version 5.13.4. The patch modifies the xdrsetpage_base function to return early if setting base to a point at the end of the page data, preventing the out-of-bounds access (Linux Kernel Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."