CVE-2021-46921
published 2024-02-27CVE-2021-46921: In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_slowpath() While this code is executed…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.24%
14.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
locking/qrwlock: Fix ordering in queued_write_lock_slowpath()
While this code is executed with the wait_lock held, a reader can
acquire the lock without holding wait_lock. The writer side loops
checking the value with the atomic_cond_read_acquire(), but only truly
acquires the lock when the compare-and-exchange is completed
successfully which isn’t ordered. This exposes the window between the
acquire and the cmpxchg to an A-B-A problem which allows reads
following the lock acquisition to observe values speculatively before
the write lock is truly acquired.
We've seen a problem in epoll where the reader does a xchg while
holding the read lock, but the writer can see a value change out from
under it.
Writer | Reader
ep_scan_ready_list() |
|- write_lock_irq() |
|- queued_write_lock_slowpath() |
|- atomic_cond_read_acquire() |
| read_lock_irqsave(&ep->lock, flags);
--> (observes value before unlock) | chain_epi_lockless()
| | epi->next = xchg(&ep->ovflist, epi);
| | read_unlock_irqrestore(&ep->lock, flags);
| |
| atomic_cmpxchg_relaxed() |
|-- READ_ONCE(ep->ovflist); |
A core can order the read of the ovflist ahead of the
atomic_cmpxchg_relaxed(). Switching the cmpxchg to use acquire
semantics addresses this issue at which point the atomic_cond_read can
be switched to use relaxed semantics.
[peterz: use try_cmpxchg()]
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.38-1 (bookworm) | linux 5.10.38-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= b519b56e378ee82caf9b079b04f5db87dedc3251 < 5902f9453a313be8fe78cbd7e7ca9dba9319fc6e | 5902f9453a313be8fe78cbd7e7ca9dba9319fc6e |
| linux | linux | >= b519b56e378ee82caf9b079b04f5db87dedc3251 < 82808cc026811fbc3ecf0c0b267a12a339eead56 | 82808cc026811fbc3ecf0c0b267a12a339eead56 |
| linux | linux | >= b519b56e378ee82caf9b079b04f5db87dedc3251 < 82fa9ced35d88581cffa4a1c856fc41fca96d80a | 82fa9ced35d88581cffa4a1c856fc41fca96d80a |
| linux | linux | >= b519b56e378ee82caf9b079b04f5db87dedc3251 < d558fcdb17139728347bccc60a16af3e639649d2 | d558fcdb17139728347bccc60a16af3e639649d2 |
| linux | linux | >= b519b56e378ee82caf9b079b04f5db87dedc3251 < 84a24bf8c52e66b7ac89ada5e3cfbe72d65c1896 | 84a24bf8c52e66b7ac89ada5e3cfbe72d65c1896 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 4.15.0 < 4.19.189 | 4.19.189 |
| linux | linux_kernel | >= 4.20.0 < 5.4.115 | 5.4.115 |
| linux | linux_kernel | >= 5.11.0 < 5.11.17 | 5.11.17 |
| linux | linux_kernel | >= 5.5.0 < 5.10.33 | 5.10.33 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2021-46921: In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_slowpath() While this code is e
osv·2024-02-27·CVSS 5.5
CVE-2021-46921 [MEDIUM] CVE-2021-46921: In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_slowpath() While this code is e
In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_slowpath() While this code is executed with the wait_lock held, a reader can acquire the lock without holding wait_lock. The writer side loops checking the value with the atomic_cond_read_acquire(), but only truly acquires the lock when the compare-and-exchange is completed successfully which isn’t ordered. This exposes the window between the acquire and the cmpxchg to an A-B-A problem which allows reads following the lock acquisition to observe values speculatively before the write lock is truly acquired. We've seen a problem in epoll where the reader does a xchg while holding the read lock, but the writer can see a value change out from under it. Writer | Reader --------
GHSA
GHSA-8j25-5vwv-hm2f: In the Linux kernel, the following vulnerability has been resolved:
locking/qrwlock: Fix ordering in queued_write_lock_slowpath()
While this code is
ghsa_unreviewed·2024-02-27
CVE-2021-46921 [MEDIUM] CWE-668 GHSA-8j25-5vwv-hm2f: In the Linux kernel, the following vulnerability has been resolved:
locking/qrwlock: Fix ordering in queued_write_lock_slowpath()
While this code is
In the Linux kernel, the following vulnerability has been resolved:
locking/qrwlock: Fix ordering in queued_write_lock_slowpath()
While this code is executed with the wait_lock held, a reader can
acquire the lock without holding wait_lock. The writer side loops
checking the value with the atomic_cond_read_acquire(), but only truly
acquires the lock when the compare-and-exchange is completed
successfully which isn’t ordered. This exposes the window between the
acquire and the cmpxchg to an A-B-A problem which allows reads
following the lock acquisition to observe values speculatively before
the write lock is truly acquired.
We've seen a problem in epoll where the reader does a xchg while
holding the read lock, but the writer can see a value change out from
under it.
Writer | Reader
ep_s
Red Hat
kernel: locking/qrwlock: Fix ordering in queued_write_lock_slowpath()
vendor_redhat·2024-02-27·CVSS 5.5
CVE-2021-46921 [MEDIUM] CWE-402 kernel: locking/qrwlock: Fix ordering in queued_write_lock_slowpath()
kernel: locking/qrwlock: Fix ordering in queued_write_lock_slowpath()
In the Linux kernel, the following vulnerability has been resolved:
locking/qrwlock: Fix ordering in queued_write_lock_slowpath()
While this code is executed with the wait_lock held, a reader can
acquire the lock without holding wait_lock. The writer side loops
checking the value with the atomic_cond_read_acquire(), but only truly
acquires the lock when the compare-and-exchange is completed
successfully which isn’t ordered. This exposes the window between the
acquire and the cmpxchg to an A-B-A problem which allows reads
following the lock acquisition to observe values speculatively before
the write lock is truly acquired.
We've seen a problem in epoll where the reader does a xchg while
holding the read lock, but the wr
Debian
CVE-2021-46921: linux - In the Linux kernel, the following vulnerability has been resolved: locking/qrw...
vendor_debian·2021·CVSS 5.5
CVE-2021-46921 [MEDIUM] CVE-2021-46921: linux - In the Linux kernel, the following vulnerability has been resolved: locking/qrw...
In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_slowpath() While this code is executed with the wait_lock held, a reader can acquire the lock without holding wait_lock. The writer side loops checking the value with the atomic_cond_read_acquire(), but only truly acquires the lock when the compare-and-exchange is completed successfully which isn’t ordered. This exposes the window between the acquire and the cmpxchg to an A-B-A problem which allows reads following the lock acquisition to observe values speculatively before the write lock is truly acquired. We've seen a problem in epoll where the reader does a xchg while holding the read lock, but the writer can see a value change out from under it. Writer | Reader --------
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/5902f9453a313be8fe78cbd7e7ca9dba9319fc6ehttps://git.kernel.org/stable/c/82808cc026811fbc3ecf0c0b267a12a339eead56https://git.kernel.org/stable/c/82fa9ced35d88581cffa4a1c856fc41fca96d80ahttps://git.kernel.org/stable/c/84a24bf8c52e66b7ac89ada5e3cfbe72d65c1896https://git.kernel.org/stable/c/d558fcdb17139728347bccc60a16af3e639649d2https://git.kernel.org/stable/c/5902f9453a313be8fe78cbd7e7ca9dba9319fc6ehttps://git.kernel.org/stable/c/82808cc026811fbc3ecf0c0b267a12a339eead56https://git.kernel.org/stable/c/82fa9ced35d88581cffa4a1c856fc41fca96d80ahttps://git.kernel.org/stable/c/84a24bf8c52e66b7ac89ada5e3cfbe72d65c1896https://git.kernel.org/stable/c/d558fcdb17139728347bccc60a16af3e639649d2
2024-02-27
Published