CVE-2021-47351
MediumIn the Linux kernel, the following vulnerability has been resolved: ubifs: Fix races between xattr_{set|get} and listxattr operations UBIFS may occur some problems with concurrent xattr_{set|get} and listxattr operations, such as assertion failure, memory corruption, stale xattr value[1]. Fix it by importing a new rw-lock in @ubifs_inode to serilize write operations on xattr, concurrent read operations are still effective, just like ext4. [1] https://lore.kernel.org/linux-mtd/[email protected]
CVSS 3.1 score
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness type
CWE-617CVE-2021-47351 is classified as CWE-617
See CWE-617 on MITRE CWE for full details on this weakness type.
References
The following references provide additional information about CVE-2021-47351 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
PatchKernel patch commithttps://git.kernel.org/stable/c/38dde03eb239605f428f3f1e4baa73d4933a4cc6
-
PatchKernel patch commithttps://git.kernel.org/stable/c/7adc05b73d91a5e3d4ca7714fa53ad9b70c53d08
-
PatchKernel patch commithttps://git.kernel.org/stable/c/9558612cb829f2c022b788f55d6b8437d5234a82
Frequently asked questions
-
What is CVE-2021-47351?
CVE-2021-47351 is a Medium severity Linux kernel vulnerability with a CVSS score of 5.5 out of 10 . CVE-2021-47351 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2021-47351?
CVE-2021-47351 has a CVSS score of 5.5 out of 10, rated Medium severity (CVSS 3.1). The vector string is
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. -
Is there a patch available for CVE-2021-47351?
No patch is currently available for CVE-2021-47351. Monitor the NIST NVD and your Linux distribution's security advisories for updates.
-
Is CVE-2021-47351 actively exploited?
No — CVE-2021-47351 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.