---
id: CVE-2021-38199
title: >-
  fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect
  connection-setup ordering, which allows operators of remote NFSv4 servers to
  cause a denial of service (hanging of mounts) by arranging for those servers
  to be unreachab…
summary: >-
  fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect
  connection-setup ordering, which allows operators of remote NFSv4 servers to
  cause a denial of service (hanging of mounts) by arranging for those servers
  to be unreachab…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: netapp
product: hci_management_node
affected:
  - linux_kernel < 5.13.4
  - hci_bootstrap_os
  - hci_management_node
  - solidfire
  - element_software
  - debian_linux = 9.0
  - debian_linux = 11.0
patched:
  - linux_kernel 5.13.4
published: '2021-08-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:39.333'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-38199'
references:
  - url: 'https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.4'
    label: cve@mitre.org
  - url: >-
      https://github.com/torvalds/linux/commit/dd99e9f98fbf423ff6d365b37a98e8879170f17c
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20210902-0010/'
    label: cve@mitre.org
  - url: 'https://www.debian.org/security/2021/dsa-4978'
    label: cve@mitre.org
  - url: 'https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.4'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/torvalds/linux/commit/dd99e9f98fbf423ff6d365b37a98e8879170f17c
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210902-0010/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2021/dsa-4978'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01245
epssPercentile: 0.68361
ingestedAt: '2026-10-08T22:11:53.740Z'
---

## Overview

fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.

## Affected

- `linux_kernel < 5.13.4`
- `hci_bootstrap_os`
- `hci_management_node`
- `solidfire`
- `element_software`
- `debian_linux = 9.0`
- `debian_linux = 11.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.13.4`
