kernel: Improper lock operation in btrfs
Published Mar 23, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.40%
Description
A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem.
Affected products
- Vendor n/a Product Kernel Defaultunknown
Affected
- kernel 5.15 rc6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Kernel | unknown | Affected
|
Configuration 1
- < 5.15
- 5.15
- 5.15
- 5.15
- 5.15
- 5.15
- 5.15
Configuration 2
- 9.0
No data.
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The vulnerability in the Linux kernel was not shipped in Red Hat Enterprise Linux 8.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2021-4149 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2026485 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-34017 Advisory
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lkml.org/lkml/2021/10/18/885 x_refsource_MISCExploitMailing ListPatchThird Party Advisory
- https://lkml.org/lkml/2021/9/13/2565 x_refsource_MISCExploitMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-4149
- https://www.cve.org/CVERecord?id=CVE-2021-4149
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-4149 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2026485 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-34017 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://lkml.org/lkml/2021/10/18/885 | x_refsource_MISCExploitMailing ListPatchThird Party Advisory | |
| https://lkml.org/lkml/2021/9/13/2565 | x_refsource_MISCExploitMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-4149 | ||
| https://www.cve.org/CVERecord?id=CVE-2021-4149 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data