U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2021-47351

Change History

New CVE Received by NIST 5/21/2024 11:15:21 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

ubifs: Fix races between xattr_{set|get} and listxattr operations

UBIFS may occur some problems with concurrent xattr_{set|get} and
listxattr operations, such as assertion failure, memory corruption,
stale xattr value[1].

Fix it by importing a new rw-lock in @ubifs_inode to serilize write
operations on xattr, concurrent read operations are still effective,
just like ext4.

[1] https://lore.kernel.org/linux-mtd/20200630130438.141649-1-houtao1@huawei.com
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/38dde03eb239605f428f3f1e4baa73d4933a4cc6 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/7adc05b73d91a5e3d4ca7714fa53ad9b70c53d08 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/9558612cb829f2c022b788f55d6b8437d5234a82 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/c0756f75c22149d20fcb7d8409827cee905eb386 [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/f4e3634a3b642225a530c292fdb1e8a4007507f5 [No types assigned]