cbcvebase.
CVE-2021-47498
published 2024-05-22

CVE-2021-47498: In the Linux kernel, the following vulnerability has been resolved: dm rq: don't queue request to blk-mq during DM suspend DM uses blk-mq's quiesce/unquiesce…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.2th percentile
In the Linux kernel, the following vulnerability has been resolved: dm rq: don't queue request to blk-mq during DM suspend DM uses blk-mq's quiesce/unquiesce to stop/start device mapper queue. But blk-mq's unquiesce may come from outside events, such as elevator switch, updating nr_requests or others, and request may come during suspend, so simply ask for blk-mq to requeue it. Fixes one kernel panic issue when running updating nr_requests and dm-mpath suspend/resume stress test.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.16-1 (bookworm)linux 5.14.16-1 (bookworm)
linuxlinux
linuxlinux>= 7b17c2f7292ba1f3f98dae3f7077f9e569653276 < 8050652810bf38241edec8717393d2446e8036f18050652810bf38241edec8717393d2446e8036f1
linuxlinux>= 7b17c2f7292ba1f3f98dae3f7077f9e569653276 < 8ca9745efe3528feb06ca4e117188038eea2d3518ca9745efe3528feb06ca4e117188038eea2d351
linuxlinux>= 7b17c2f7292ba1f3f98dae3f7077f9e569653276 < b4459b11e84092658fa195a2587aff3b9637f0e7b4459b11e84092658fa195a2587aff3b9637f0e7
linuxlinux_kernel< 5.14.145.14.14
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1
linuxlinux_kernel>= 0 < 5.14.16-15.14.16-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.