A flaw was found in nfsd. A failure to clear umask after processing an open or create operation results in wrong permissions on a newly-created objects. References: https://bugzilla.redhat.com/show_bug.cgi?id=1903303
Statement: This flaw is rated as having Low impact because of the exploitation prerequisities and the fact that the attacker could only decrease the permissions of the file or directory.
Acknowledgments: Name: J. Bruce Fields (fieldses.org)
External References: https://patchwork.kernel.org/project/linux-nfs/patch/20180403203916.GH20297@fieldses.org/
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1919911]
This was fixed for Fedora with the 4.15.18 stable kernel updates.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2021:0336 https://access.redhat.com/errata/RHSA-2021:0336
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2021:0338 https://access.redhat.com/errata/RHSA-2021:0338
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-35513