Updated: 2025-08-20 01:51:05.714935
Description:
fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some parties argue that such a subdirectory export is not intended to prevent this attack; see also the exports(5) no_subtree_check default behavior
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | MEDIUM | 5.5 |
| CVSS Version 3.x | MEDIUM | 6.5 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| CentOS 6 ELS | kernel | 2.6.32 | 6.5 | MEDIUM | Released | CLSA-2021:1632262296 | 2022-05-05 12:01:39 | |
| CentOS 7 ELS | kernel | 3.10.0 | 6.5 | MEDIUM | Released | CLSA-2024:1720468480 | 2024-07-23 17:33:58 | |
| CentOS 8.4 ELS | kernel | 4.18.0 | 6.5 | MEDIUM | Ignored | 2022-02-10 08:36:34 | Ignored due to low severity | |
| CentOS 8.5 ELS | kernel | 4.18.0 | 6.5 | MEDIUM | Ignored | 2022-02-21 05:39:38 | Ignored due to low severity | |
| CloudLinux 6 ELS | kernel | 2.6.32 | 6.5 | MEDIUM | Ignored | 2022-01-27 11:20:14 | Ignored due to low severity | |
| Oracle Linux 6 ELS | kernel | 2.6.32 | 6.5 | MEDIUM | Released | CLSA-2022:1669850228 | 2022-11-30 19:57:53 | |
| RHEL 7 ELS | kernel | 3.10.0 | 6.5 | MEDIUM | Released | CLSA-2025:1750353839 | 2025-06-20 00:28:20 | |
| Ubuntu 16.04 ELS | linux-hwe | 4.15.0 | 6.5 | MEDIUM | Ignored | 2022-09-28 08:02:32 | Ignored due to low severity | |
| Ubuntu 16.04 ELS | linux | 4.4.0 | 6.5 | MEDIUM | Not Vulnerable | 2022-01-26 05:16:14 | Ignored due to low severity | |
| Ubuntu 18.04 ELS | linux | 4.15.0 | 6.5 | MEDIUM | Ignored | 2023-03-02 04:04:07 | Ignored due to low severity |