cbcvebase.
CVE-2021-47340
published 2024-05-21

CVE-2021-47340: In the Linux kernel, the following vulnerability has been resolved: jfs: fix GPF in diFree Avoid passing inode with JFS_SBI(inode->i_sb)->ipimap == NULL to…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.4th percentile
In the Linux kernel, the following vulnerability has been resolved: jfs: fix GPF in diFree Avoid passing inode with JFS_SBI(inode->i_sb)->ipimap == NULL to diFree()[1]. GFP will appear: struct inode *ipimap = JFS_SBI(ip->i_sb)->ipimap; struct inomap *imap = JFS_IP(ipimap)->i_imap; JFS_IP() will return invalid pointer when ipimap == NULL Call Trace: diFree+0x13d/0x2dc0 fs/jfs/jfs_imap.c:853 [1] jfs_evict_inode+0x2c9/0x370 fs/jfs/inode.c:154 evict+0x2ed/0x750 fs/inode.c:578 iput_final fs/inode.c:1654 [inline] iput.part.0+0x3fe/0x820 fs/inode.c:1680 iput+0x58/0x70 fs/inode.c:1670

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 62aff86fdf18657d9eca7878654415f94f16d027 < 7bde24bde490f3139eee147efc6d60d6040fe9757bde24bde490f3139eee147efc6d60d6040fe975
linuxlinux>= 62aff86fdf18657d9eca7878654415f94f16d027 < 745c9a59422c63f661f4374ed5181740db4130a1745c9a59422c63f661f4374ed5181740db4130a1
linuxlinux>= 62aff86fdf18657d9eca7878654415f94f16d027 < 49def1b0644892e3b113673c13d650c3060b43bc49def1b0644892e3b113673c13d650c3060b43bc
linuxlinux>= 62aff86fdf18657d9eca7878654415f94f16d027 < aff8d95b69051d0cf4acc3d91f22299fdbb9dfb3aff8d95b69051d0cf4acc3d91f22299fdbb9dfb3
linuxlinux>= 62aff86fdf18657d9eca7878654415f94f16d027 < a21e5cb1a64c904f1f0ef7b2d386fc7d2b1d2ce2a21e5cb1a64c904f1f0ef7b2d386fc7d2b1d2ce2
linuxlinux>= 62aff86fdf18657d9eca7878654415f94f16d027 < 8018936950360f1c503bb385e158cfc5e4945d188018936950360f1c503bb385e158cfc5e4945d18
linuxlinux>= 62aff86fdf18657d9eca7878654415f94f16d027 < 3bb27e27240289b47d3466f647a55c567adbdc3a3bb27e27240289b47d3466f647a55c567adbdc3a
linuxlinux>= 62aff86fdf18657d9eca7878654415f94f16d027 < 42f102ea1943ecb10a0756bf75424de5d1d5beed42f102ea1943ecb10a0756bf75424de5d1d5beed
linuxlinux>= 62aff86fdf18657d9eca7878654415f94f16d027 < 9d574f985fe33efd6911f4d752de6f485a1ea7329d574f985fe33efd6911f4d752de6f485a1ea732
linuxlinux_kernel< 4.4.2764.4.276
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 4.10 < 4.14.2404.14.240
linuxlinux_kernel>= 4.15 < 4.19.1984.19.198
linuxlinux_kernel>= 4.20 < 5.4.1335.4.133
linuxlinux_kernel>= 4.5 < 4.9.2764.9.276
linuxlinux_kernel>= 5.11 < 5.12.185.12.18
linuxlinux_kernel>= 5.13 < 5.13.35.13.3
linuxlinux_kernel>= 5.5 < 5.10.515.10.51

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.