Review reviewHigh

CVE-2021-47600

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: dm btree remove: fix use after free in rebalance_children() Move dm_tm_unlock() after dm_tm_dec().

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2024.06.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: dm btree remove: fix use after free in rebalance_children() Move dm_tm_unlock() after dm_tm_dec().

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 < a48f6a2bf33734ec5669ee03067dfb6c5b4818d6, >= 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 < 66ea642af6fd4eacb5d0271a922130fcf8700424, >= 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 < b03abd0aa09c05099f537cb05b8460c4298f0861, >= 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 < 293f957be5e39720778fb1851ced7f5fba6d51c3, >= 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 < 501ecd90efdc9b2edc6c28852ecd098a4adf8f00, >= 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 < 0e21e6cd5eebfc929ac5fa3b97ca2d4ace3cb6a3, >= 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 < 607beb420b3fe23b948a9bf447d993521a02fbbb, >= 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 < 1b8d2789dad0005fd5e7d35dab26a8e1203fb6da, >= 3.2, < 4.4.296, >= 4.5 < 4.9.294, >= 4.10 < 4.14.259, >= 4.15 < 4.19.222, >= 4.20 < 5.4.168, >= 5.5 < 5.10.88, >= 5.11 < 5.15.11
Fixed versions
4.4.296, 4.9.294, 4.14.259, 4.19.222, 5.4.168, 5.10.88, 5.15.11

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416