SB20240608177 - Race condition in Linux kernel ocfs2
Published: June 8, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Race condition (CVE-ID: CVE-2021-47493)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition within the ocfs2_test_bg_bit_allocatable() function in fs/ocfs2/suballoc.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5043fbd294f5909a080ade0f04b70a4da9e122b7
- https://git.kernel.org/stable/c/2e382600e8856ea654677b5134ee66e03ea72bc2
- https://git.kernel.org/stable/c/6f1b228529ae49b0f85ab89bcdb6c365df401558
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.77
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.16
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15