CVE-2020-35513
Published: 26 January 2021
Summary
CVE-2020-35513 is a medium-severity Privilege Dropping / Lowering Errors (CWE-271) vulnerability in Linux Linux Kernel. Its CVSS base score is 4.9 (Medium).
Operationally, ranked in the top 44.8% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2020-23180
Vulnerability details
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by the…
more
other process that is not using new NFSv4.2. A user with access to the NFS could use this flaw to starve the resources causing denial of service.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Mandates lowering or adjusting privileges to match new operational needs, reducing errors in privilege dropping during transfers.