Lucene search

K
f5F5F5:K01311152
HistoryApr 12, 2022 - 12:00 a.m.

K01311152 : Linux kernel vulnerabilities CVE-2020-36322 and CVE-2021-28950

2022-04-1200:00:00
my.f5.com
17

6.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.3%

Security Advisory Description

An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. fuse_do_getattr() calls make_bad_inode() in inappropriate situations, causing a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950.

An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A “stall on CPU” can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1.

Impact

There is no impact; F5 products are not affected by this vulnerability.