A critical vulnerability that could allow remote code execution with root privileges on unpatched My Cloud OS 5 devices has been patched by Western Digital.
See also: Western Digital: Critical bug in EdgeRover desktop app affects Windows/macOS

This is an out-of-bounds heap read/write on the Samba vfs_fruit VFS.
It can be exploited by unauthenticated malicious users in low-sophistication attacks targeting My Cloud devices running vulnerable firmware versions.
While default configurations are vulnerable to attack, threat actors need write access to a file's extended attributes. It could also be a guest or unauthenticated user if they are allowed write access to extended file attributes, according to the Samba team.
Western Digital addressed the vulnerability by removing the VFS module "fruit" from the list of configured VFS objects and changing the EA support configurations in My Cloud OS 5 Firmware 5.21.104, released on March 23, 2022.
The American hard drive manufacturer advises customers to update their devices to the latest firmware by clicking on the update notification as soon as possible.
See also: Linux bug gives root privileges to all major distributions

The list of devices considered vulnerable to CVE-2021-44142 attacks includes:
- My Cloud PR2100
- My Cloud PR4100
- My Cloud EX4100
- My Cloud EX2 Ultra
- My Cloud Mirror Gen 2
- My Cloud DL2100
- My Cloud DL4100
- My Cloud EX2100
- My Cloud
- WD Cloud
This week, Western Digital patched another critical vulnerability in its open-source Netatalk Apple File Protocol file server, used to access network shares and perform Time Machine backups.
See also: Samba bug: Allows remote code execution as root
The error was addressed by removing the Netatalk service and removing it from the My Cloud OS with firmware update 5.19.117.
After installing the firmware to the latest version, the Netatalk service will no longer be available.
However, users of My Cloud devices can still configure them to access network shares via SMB.
