5.5
CVSSv3

CVE-2021-45868

Published: 18/03/2022 Updated: 04/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In the Linux kernel prior to 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for example, lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

netapp h300s firmware -

netapp h700s firmware -

netapp h300e firmware -

netapp h500e firmware -

netapp h700e firmware -

netapp h410s firmware -

netapp h410c firmware -

netapp h500s firmware -

Vendor Advisories

In the Linux kernel before 5153, fs/quota/quota_treec does not validate the block number in the quota tree (on disk) This can, for example, lead to a kernel/locking/rwsemc use-after-free if there is a corrupted quota file ...