PT-2021-8013 · Linux · Linux Kernel

Xiao Ni

·

Published

2021-04-26

·

Updated

2025-01-09

·

CVE-2021-47066

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the async xor function in the Linux kernel, which can cause data corruption problems due to incorrect calculation of xor values when sharing one page if PAGE SIZE is not equal to stripe size. In RMW mode, the parity page is used as a source page, and the ASYNC TX XOR DROP DST flag is set before calculating the xor value in ops run prexor5. However, it only needs src list, resulting in incorrect xor values. This problem can be reproduced on a POWER8 machine using specific steps, including creating a RAID device, formatting it with XFS, and mounting it.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-01830
CVE-2021-47066

Affected Products

Linux Kernel