Medium severity6.1NVD Advisory· Published Apr 19, 2021· Updated Jun 17, 2026
CVE-2021-20208
CVE-2021-20208
Description
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cifs-utils/cifs-utilsdescription
- Range: <6.13
- osv-coords10 versionspkg:rpm/opensuse/cifs-utils&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/cifs-utils&distro=openSUSE%20Tumbleweedpkg:rpm/suse/cifs-utils&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/cifs-utils&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/cifs-utils&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/cifs-utils&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/cifs-utils&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/cifs-utils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/cifs-utils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/cifs-utils&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 6.9-lp152.2.3.1+ 9 more
- (no CPE)range: < 6.9-lp152.2.3.1
- (no CPE)range: < 6.13-1.3
- (no CPE)range: < 6.9-3.14.1
- (no CPE)range: < 6.9-3.14.1
- (no CPE)range: < 6.9-5.9.1
- (no CPE)range: < 6.9-13.14.1
- (no CPE)range: < 6.9-3.14.1
- (no CPE)range: < 6.9-13.14.1
- (no CPE)range: < 6.9-3.14.1
- (no CPE)range: < 6.9-13.14.1
Patches
Vulnerability mechanics
References
5- bugzilla.samba.org/show_bug.cginvdIssue TrackingPatchVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2W4HSDIWXXNQBUW5ZS37RQMLJ7THK5AS/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/66WJ3SVBHCSNQZAWSGLB6FBOCFU45FFG/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z4BZSJXROEFHYATAAHHRR6P3HUSMPQB3/nvd
News mentions
0No linked articles in our index yet.