4.7
CVSSv3

CVE-2021-28964

Published: 22/03/2021 Updated: 07/11/2023
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 170
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A race condition exists in get_old_root in fs/btrfs/ctree.c in the Linux kernel up to and including 5.11.8. It allows malicious users to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

fedoraproject fedora 32

fedoraproject fedora 33

fedoraproject fedora 34

debian debian linux 9.0

netapp cloud backup -

netapp solidfire baseboard management controller firmware -

netapp aff_a250_firmware -

netapp fas_500f_firmware -

Vendor Advisories

Several security issues were fixed in the Linux kernel ...
kernel: refcount leak in llcp_sock_bind() (CVE-2020-25670) kernel: refcount leak in llcp_sock_connect() (CVE-2020-25671) kernel: memory leak in llcp_sock_connect() (CVE-2020-25672) An issue was discovered in the Linux kernel related to mm/gupc and mm/huge_memoryc The get_user_pages (aka gup) implementation, when used for a copy-on-write page, do ...
A race condition was discovered in get_old_root in fs/btrfs/ctreec in the Linux kernel through 5118 It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc ...
An issue was discovered in the Linux kernel Fastrpc_internal_invoke in drivers/misc/fastrpcc does not prevent user applications from sending kernel RPC messages This is a related issue to CVE-2019-2308 (CVE-2021-28375) A flaw was found in the Linux kernel The rtw_wx_set_scan driver allows writing beyond the end of the ->ssid[] array The hi ...
A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_bufferc in the Linux kernel before 539 allows attackers to cause a denial of service (memory consumption), aka CID-ab612b1daf41 (CVE-2019-19060) A bypass was found for the Spectre v1 hardening in the eBPF engine of the Linux kernel The code in the kernel/bpf/verifier ...
A race condition was discovered in get_old_root in fs/btrfs/ctreec in the Linux kernel through 5118 It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc ...