PT-2021-4256 · Linux+3 · Linux Kernel+3
Naohiro Aota
·
Published
2021-07-07
·
Updated
2023-05-17
·
CVE-2021-38203
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.13.4
Description
The issue is related to the btrfs implementation in the Linux kernel, which can lead to a denial of service due to uncontrolled memory allocation. This can occur when there is a shortage of free space in the system space info, and processes trigger the allocation of new system chunks. As a result, an attacker can cause a deadlock.
Recommendations
For Linux kernel versions prior to 5.13.4, update to version 5.13.4 or later to resolve the issue. As a temporary workaround, consider restricting system chunk allocation during times of low free space in the system space info to minimize the risk of exploitation.
Exploit
Fix
DoS
Improper Locking
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Linux Kernel
Ubuntu