CVE-2021-38203
published 2021-08-08CVE-2021-38203: btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.36%
29.2th percentile
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux_kernel | < 5.13.4 | 5.13.4 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| msrc | cbl2_kernel_5.10.78.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_kernel_5.10.60.1-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5fjr-c5p8-hxvj: btrfs in the Linux kernel before 5
ghsa_unreviewed·2022-05-24
CVE-2021-38203 [MEDIUM] CWE-667 GHSA-5fjr-c5p8-hxvj: btrfs in the Linux kernel before 5
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
OSV
linux-oem-5.13 vulnerabilities
osv·2021-09-29·CVSS 5.5
CVE-2021-41073 [MEDIUM] linux-oem-5.13 vulnerabilities
linux-oem-5.13 vulnerabilities
Valentina Palmiotti discovered that the io_uring subsystem in the Linux
kernel could be coerced to free adjacent memory. A local attacker could use
this to execute arbitrary code. (CVE-2021-41073)
Benedict Schlueter discovered that the BPF subsystem in the Linux kernel
did not properly protect against Speculative Store Bypass (SSB) side-
channel attacks in some situations. A local attacker could possibly use
this to expose sensitive information. (CVE-2021-34556)
Piotr Krysiuk discovered that the BPF subsystem in the Linux kernel did not
properly protect against Speculative Store Bypass (SSB) side-channel
attacks in some situations. A local attacker could possibly use this to
expose sensitive information. (CVE-2021-35477)
Murray McAllister discovered that
OSV
CVE-2021-38203: btrfs in the Linux kernel before 5
osv·2021-08-08·CVSS 5.5
CVE-2021-38203 [MEDIUM] CVE-2021-38203: btrfs in the Linux kernel before 5
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2021-09-29·CVSS 5.5
CVE-2021-38204 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Valentina Palmiotti discovered that the io_uring subsystem in the Linux
kernel could be coerced to free adjacent memory. A local attacker could use
this to execute arbitrary code. (CVE-2021-41073)
Benedict Schlueter discovered that the BPF subsystem in the Linux kernel
did not properly protect against Speculative Store Bypass (SSB) side-
channel attacks in some situations. A local attacker could possibly use
this to expose sensitive information. (CVE-2021-34556)
Piotr Krysiuk discovered that the BPF subsystem in the Linux kernel did not
properly protect against Speculative Store Bypass (SSB) side-channel
attacks in some situations. A local attacker could possibly use this to
expos
Microsoft
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of fre
vendor_msrc·2021-08-10·CVSS 5.5
CVE-2021-38203 [MEDIUM] CWE-667 btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of fre
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products
Red Hat
kernel: btrfs: deadlock via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info
vendor_redhat·2021-07-07·CVSS 5.5
CVE-2021-38203 [MEDIUM] CWE-667 kernel: btrfs: deadlock via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info
kernel: btrfs: deadlock via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
A flaw was found in the btrfs filesystem in the Linux kernel that allows attackers to cause a denial of service via processes that trigger allocation of new system chunks when there is a shortage of free space in the system space_info. The highest threat from this vulnerability is to system availability.
Statement: There was no shipped kernel version that was seen affected by this problem. These file
Debian
CVE-2021-38203: linux - btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of se...
vendor_debian·2021·CVSS 5.5
CVE-2021-38203 [MEDIUM] CVE-2021-38203: linux - btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of se...
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.4https://github.com/torvalds/linux/commit/1cb3db1cf383a3c7dbda1aa0ce748b0958759947https://security.netapp.com/advisory/ntap-20210902-0010/https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.4https://github.com/torvalds/linux/commit/1cb3db1cf383a3c7dbda1aa0ce748b0958759947https://security.netapp.com/advisory/ntap-20210902-0010/
2021-08-08
Published