PT-2021-8013 · Linux · Linux Kernel
Xiao Ni
·
Published
2021-04-26
·
Updated
2025-01-09
·
CVE-2021-47066
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the async xor function in the Linux kernel, which can cause data corruption problems due to incorrect calculation of xor values when sharing one page if PAGE SIZE is not equal to stripe size. In RMW mode, the parity page is used as a source page, and the ASYNC TX XOR DROP DST flag is set before calculating the xor value in ops run prexor5. However, it only needs src list, resulting in incorrect xor values. This problem can be reproduced on a POWER8 machine using specific steps, including creating a RAID device, formatting it with XFS, and mounting it.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel