PT-2021-4245 · Linux+7 · Linux Kernel+7

Published

2021-08-30

·

Updated

2023-08-14

·

CVE-2021-40490

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions up to 5.13.13
Description A race condition was discovered in the ext4 write inline data end function in the ext4 subsystem. This issue may allow an attacker to impact the integrity, availability, and confidentiality of data. The vulnerability is caused by concurrent execution using a shared resource with incorrect synchronization, leading to a race condition.
Recommendations For Linux kernel versions up to 5.13.13, update to a version later than 5.13.13 to resolve the issue. As a temporary workaround, consider restricting access to the ext4 write inline data end function in the fs/ext4/inline.c file to minimize the risk of exploitation.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2723
ALT-PU-2021-2749
ALT-PU-2021-2778
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2022-1205
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-6595
BDU:2021-04853
CESA-2022_1988
CVE-2021-40490
DLA-2785-1
DLA-2843-1
DSA-4978-1
MGASA-2021-0418
MGASA-2021-0460
OESA-2021-1366
OPENSUSE-SU-2021:1357-1
OPENSUSE-SU-2021:1365-1
OPENSUSE-SU-2021:3338-1
OPENSUSE-SU-2021:3387-1
OPENSUSE-SU-2021:3447-1
OPENSUSE-SU-2021:3876-1
OPENSUSE-SU-2021_1357-1
OPENSUSE-SU-2021_1365-1
OPENSUSE-SU-2021_3338-1
OPENSUSE-SU-2021_3387-1
OPENSUSE-SU-2021_3447-1
OPENSUSE-SU-2021_3876-1
RHSA-2022:1988
RHSA-2022_1988
SUSE-SU-2021:3337-1
SUSE-SU-2021:3338-1
SUSE-SU-2021:3339-1
SUSE-SU-2021:3386-1
SUSE-SU-2021:3387-1
SUSE-SU-2021:3388-1
SUSE-SU-2021:3389-1
SUSE-SU-2021:3415-1
SUSE-SU-2021:3447-1
SUSE-SU-2021:3876-1
SUSE-SU-2021:3929-1
SUSE-SU-2021:3935-1
SUSE-SU-2021:3969-1
SUSE-SU-2021:3972-1
USN-5096-1
USN-5113-1
USN-5114-1
USN-5115-1
USN-5116-1
USN-5116-2
USN-5120-1
USN-5343-1

Affected Products

Alt Linux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu