cbcvebase.
CVE-2021-47342
published 2024-05-21

CVE-2021-47342: In the Linux kernel, the following vulnerability has been resolved: ext4: fix possible UAF when remounting r/o a mmp-protected file system After commit…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: fix possible UAF when remounting r/o a mmp-protected file system After commit 618f003199c6 ("ext4: fix memory leak in ext4_fill_super"), after the file system is remounted read-only, there is a race where the kmmpd thread can exit, causing sbi->s_mmp_tsk to point at freed memory, which the call to ext4_stop_mmpd() can trip over. Fix this by only allowing kmmpd() to exit when it is stopped via ext4_stop_mmpd(). Bug-Report-Link:

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 5.10.51 < 5.10.775.10.77
linuxlinux>= 5.12.18 < 5.135.13
linuxlinux>= 5e4f5138bd8522ebe231a137682d3857209a2c07 < b663890d854403e566169f7e90aed5cd6ff64f6bb663890d854403e566169f7e90aed5cd6ff64f6b
linuxlinux>= 618f003199c6188e01472b03cdbba227f1dc5f24 < 61bb4a1c417e5b95d9edb4f887f131de32e419cb61bb4a1c417e5b95d9edb4f887f131de32e419cb
linuxlinux>= eb7b40d9d3785f7a131fb0b1f89bb6efa46c1833 < 7ed572cdf11081f8f9e07abd4bea56a3f2c4edbd7ed572cdf11081f8f9e07abd4bea56a3f2c4edbd
linuxlinux_kernel< 5.10.775.10.77
linuxlinux_kernel>= 0 < 5.10.84-15.10.84-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 5.11 < 5.13.35.13.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.