CVE-2021-28964

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc.

References

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=dbcc7d57bffc0c8cac9dac11bec548597d59a6a5

https://lists.fedoraproject.org/archives/list/[email protected]/message/PTRNPQTZ4GVS46SZ4OBXY5YDOGVPSTGQ/

https://lists.fedoraproject.org/archives/list/[email protected]/message/4VCKIOXCOZGXBEZMO5LGGV5MWCHO6FT3/

https://lists.fedoraproject.org/archives/list/[email protected]/message/T2S3I4SLRNRUQDOFYUS6IUAZMQNMPNLG/

https://security.netapp.com/advisory/ntap-20210430-0003/

https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html

https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html

Details

Source: MITRE

Published: 2021-03-22

Updated: 2021-06-23

Type: CWE-362

Risk Information

CVSS v2

Base Score: 1.9

Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 3.4

Severity: LOW

CVSS v3

Base Score: 4.7

Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 1

Severity: MEDIUM

Tenable Plugins

View all (40 total)

IDNameProductFamilySeverity
154404EulerOS 2.0 SP3 : kernel (EulerOS-SA-2021-2588)NessusHuawei Local Security Checks
high
153271EulerOS 2.0 SP2 : kernel (EulerOS-SA-2021-2392)NessusHuawei Local Security Checks
high
151897Slackware 14.2 : Slackware 14.2 kernel (SSA:2021-202-01)NessusSlackware Local Security Checks
high
151767EulerOS 2.0 SP5 : kernel (EulerOS-SA-2021-2221)NessusHuawei Local Security Checks
high
151756openSUSE 15 Security Update : kernel (openSUSE-SU-2021:1977-1)NessusSuSE Local Security Checks
critical
151730openSUSE 15 Security Update : kernel (openSUSE-SU-2021:1975-1)NessusSuSE Local Security Checks
critical
151307EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2021-2075)NessusHuawei Local Security Checks
high
151240EulerOS 2.0 SP9 : kernel (EulerOS-SA-2021-2062)NessusHuawei Local Security Checks
high
151238EulerOS 2.0 SP9 : kernel (EulerOS-SA-2021-2051)NessusHuawei Local Security Checks
high
151229EulerOS Virtualization 3.0.6.6 : kernel (EulerOS-SA-2021-2040)NessusHuawei Local Security Checks
high
151042EulerOS 2.0 SP8 : kernel (EulerOS-SA-2021-1983)NessusHuawei Local Security Checks
high
150985Debian DLA-2689-1 : linux security updateNessusDebian Local Security Checks
high
150984Debian DLA-2690-1 : linux-4.19 security updateNessusDebian Local Security Checks
high
150927SUSE SLES15 Security Update : kernel (SUSE-SU-2021:1975-1)NessusSuSE Local Security Checks
critical
150901SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2021:1977-1)NessusSuSE Local Security Checks
critical
150463OracleVM 3.4 : Unbreakable / etc (OVMSA-2021-0016)NessusOracleVM Local Security Checks
high
150292Ubuntu 20.04 LTS / 20.10 : Linux kernel vulnerabilities (USN-4984-1)NessusUbuntu Local Security Checks
medium
150271EulerOS Virtualization 2.9.1 : kernel (EulerOS-SA-2021-1967)NessusHuawei Local Security Checks
high
150253EulerOS Virtualization 2.9.0 : kernel (EulerOS-SA-2021-1971)NessusHuawei Local Security Checks
high
150233Ubuntu 18.04 LTS / 20.04 LTS : Linux kernel vulnerabilities (USN-4982-1)NessusUbuntu Local Security Checks
medium
150155Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4979-1)NessusUbuntu Local Security Checks
medium
149892openSUSE Security Update : the Linux Kernel (openSUSE-2021-758)NessusSuSE Local Security Checks
critical
149872Amazon Linux AMI : kernel (ALAS-2021-1503)NessusAmazon Linux Local Security Checks
high
149717SUSE SLES15 Security Update : kernel (SUSE-SU-2021:1624-1)NessusSuSE Local Security Checks
high
149491SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1596-1)NessusSuSE Local Security Checks
high
149462SUSE SLES15 Security Update : kernel (SUSE-SU-2021:1573-1)NessusSuSE Local Security Checks
high
149421Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2021-9222)NessusOracle Linux Local Security Checks
high
149420Oracle Linux 7 : Unbreakable Enterprise kernel-container (ELSA-2021-9223)NessusOracle Linux Local Security Checks
high
149407Ubuntu 20.04 LTS : Linux kernel (OEM) vulnerabilities (USN-4948-1)NessusUbuntu Local Security Checks
high
149357Oracle Linux 7 / 8 : Unbreakable Enterprise kernel (ELSA-2021-9220)NessusOracle Linux Local Security Checks
high
149356Oracle Linux 7 / 8 : Unbreakable Enterprise kernel-container (ELSA-2021-9221)NessusOracle Linux Local Security Checks
high
149296Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2021-9215)NessusOracle Linux Local Security Checks
high
148919Amazon Linux 2 : kernel (ALAS-2021-1627)NessusAmazon Linux Local Security Checks
high
148747SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2021:1238-1)NessusSuSE Local Security Checks
critical
148700SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1210-1)NessusSuSE Local Security Checks
high
148698SUSE SLES15 Security Update : kernel (SUSE-SU-2021:1211-1)NessusSuSE Local Security Checks
critical
148509SUSE SLES12 Security Update : kernel (SUSE-SU-2021:1175-1)NessusSuSE Local Security Checks
medium
148438openSUSE Security Update : the Linux Kernel (openSUSE-2021-532)NessusSuSE Local Security Checks
critical
148205Fedora 32 : kernel (2021-9503fffad9)NessusFedora Local Security Checks
high
148156Fedora 33 : kernel (2021-68b0dd2373)NessusFedora Local Security Checks
high