CVE-2021-20321

Related Vulnerabilities: CVE-2021-20321  

A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS. A local user could use this flaw to crash the system.

Description

A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS. A local user could use this flaw to crash the system.

Mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Additional Information

  • Bugzilla 2013242: CVE-2021-20321 kernel: In Overlayfs missing a check for a negative dentry before calling vfs_rename()
  • FAQ: Frequently asked questions about CVE-2021-20321