Review reviewHigh

CVE-2021-47254

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix use-after-free in gfs2_glock_shrink_scan The GLF_LRU flag is checked under lru_lock in gfs2_glock_remove_from_lru() to remove the glock from the lru list in __gfs2_glock_put(). On the shrink scan path, the same flag is cleared under lru_lock but because of cond_resched_lock(&lru_lock) in gfs2_dispose_glock_lru(), progress on the put side can be made without deleting the glock from the lru list. Keep GLF_LRU across the race window opened by cond_resched_lock(&lru_lock) to ensure correct behavior on both sides - cle...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.05.22
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix use-after-free in gfs2_glock_shrink_scan The GLF_LRU flag is checked under lru_lock in gfs2_glock_remove_from_lru() to remove the glock from the lru list in __gfs2_glock_put(). On the shrink scan path, the same flag is cleared under lru_lock but because of cond_resched_lock(&lru_lock) in gfs2_dispose_glock_lru(), progress on the put side can be made without deleting the glock from the lru list. Keep GLF_LRU across the race window opened by cond_resched_lock(&lru_lock) to ensure correct behavior on both sides - cle...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 6948c6bc17d666663a84c124b3176039e64a58f4 < 38ce329534500bf4ae71f81df6a37a406cf187b4, >= b568ed385a18c0ddbe41862b69088b636550a04f < 92869945cc5b78ee8a1ef90336fe070893e3458a, >= 762bb3528249604bc680a9df635e8995740176de < 0364742decb0f02bc183404868b82896f7992595, >= bac8520892812dada1ac93f27d96317470d24b1f < 094bf5670e762afa243d2c41a5c4ab71c7447bf4, >= 7881ef3f33bb80f459ea6020d1e021fc524a6348 < 86fd5b27db743a0ce0cc245e3a34813b2aa6ec1d, >= 7881ef3f33bb80f459ea6020d1e021fc524a6348 < a61156314b66456ab6a291ed5deba1ebd002ab3c, >= 7881ef3f33bb80f459ea6020d1e021fc524a6348 < e87ef30fe73e7e10d2c85bdcc778dcec24dca553, >= 7881ef3f33bb80f459ea6020d1e021fc524a6348 < 1ab19c5de4c537ec0d9b21020395a5b5a6c059b2, >= 1e7a416fb765c9072479dc424780c0937ba99270, >= dcbdbe13796ffa561510d2686a6318564e728bbd, >= 4.4.181 < 4.4.274, >= 4.9.180 < 4.9.274, >= 4.14.123 < 4.14.238, >= 4.19.47 < 4.19.196, >= 5.0.20 < 5.1, >= 5.1.6 < 5.2, >= 5.2, >= 5.1.6 < 5.4.127, >= 5.5 < 5.10.45, >= 5.11 < 5.12.12
Fixed versions
4.4.274, 4.9.274, 4.14.238, 4.19.196, 5.1, 5.4.127, 5.10.45, 5.12.12

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416