cbcvebase.
CVE-2021-47351
published 2024-05-21

CVE-2021-47351: In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix races between xattr_{set|get} and listxattr operations UBIFS may occur some…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix races between xattr_{set|get} and listxattr operations UBIFS may occur some problems with concurrent xattr_{set|get} and listxattr operations, such as assertion failure, memory corruption, stale xattr value[1]. Fix it by importing a new rw-lock in @ubifs_inode to serilize write operations on xattr, concurrent read operations are still effective, just like ext4. [1] https://lore.kernel.org/linux-mtd/[email protected]

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux
linuxlinux>= 1e51764a3c2ac05a23a22b2a95ddee4d9bffb16d < 7adc05b73d91a5e3d4ca7714fa53ad9b70c53d087adc05b73d91a5e3d4ca7714fa53ad9b70c53d08
linuxlinux>= 1e51764a3c2ac05a23a22b2a95ddee4d9bffb16d < 38dde03eb239605f428f3f1e4baa73d4933a4cc638dde03eb239605f428f3f1e4baa73d4933a4cc6
linuxlinux>= 1e51764a3c2ac05a23a22b2a95ddee4d9bffb16d < 9558612cb829f2c022b788f55d6b8437d5234a829558612cb829f2c022b788f55d6b8437d5234a82
linuxlinux>= 1e51764a3c2ac05a23a22b2a95ddee4d9bffb16d < c0756f75c22149d20fcb7d8409827cee905eb386c0756f75c22149d20fcb7d8409827cee905eb386
linuxlinux>= 1e51764a3c2ac05a23a22b2a95ddee4d9bffb16d < f4e3634a3b642225a530c292fdb1e8a4007507f5f4e3634a3b642225a530c292fdb1e8a4007507f5
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 2.6.27 < 5.4.1335.4.133
linuxlinux_kernel>= 5.11 < 5.12.185.12.18
linuxlinux_kernel>= 5.13 < 5.13.35.13.3
linuxlinux_kernel>= 5.5 < 5.10.515.10.51

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.