{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2021-47493","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-22T06:20:56.201Z","datePublished":"2024-05-22T08:19:41.419Z","dateUpdated":"2026-08-05T08:48:03.801Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:48:03.801Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix race between searching chunks and release journal_head from buffer_head\n\nEncountered a race between ocfs2_test_bg_bit_allocatable() and\njbd2_journal_put_journal_head() resulting in the below vmcore.\n\n  PID: 106879  TASK: ffff880244ba9c00  CPU: 2   COMMAND: \"loop3\"\n  Call trace:\n    panic\n    oops_end\n    no_context\n    __bad_area_nosemaphore\n    bad_area_nosemaphore\n    __do_page_fault\n    do_page_fault\n    page_fault\n      [exception RIP: ocfs2_block_group_find_clear_bits+316]\n    ocfs2_block_group_find_clear_bits [ocfs2]\n    ocfs2_cluster_group_search [ocfs2]\n    ocfs2_search_chain [ocfs2]\n    ocfs2_claim_suballoc_bits [ocfs2]\n    __ocfs2_claim_clusters [ocfs2]\n    ocfs2_claim_clusters [ocfs2]\n    ocfs2_local_alloc_slide_window [ocfs2]\n    ocfs2_reserve_local_alloc_bits [ocfs2]\n    ocfs2_reserve_clusters_with_limit [ocfs2]\n    ocfs2_reserve_clusters [ocfs2]\n    ocfs2_lock_refcount_allocators [ocfs2]\n    ocfs2_make_clusters_writable [ocfs2]\n    ocfs2_replace_cow [ocfs2]\n    ocfs2_refcount_cow [ocfs2]\n    ocfs2_file_write_iter [ocfs2]\n    lo_rw_aio\n    loop_queue_work\n    kthread_worker_fn\n    kthread\n    ret_from_fork\n\nWhen ocfs2_test_bg_bit_allocatable() called bh2jh(bg_bh), the\nbg_bh->b_private NULL as jbd2_journal_put_journal_head() raced and\nreleased the jounal head from the buffer head.  Needed to take bit lock\nfor the bit 'BH_JournalHead' to fix this race."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable path is reached via local filesystem operations (write/create → ocfs2_file_write_iter / namei → ocfs2_reserve_clusters → ocfs2_block_group_find_clear_bits → ocfs2_test_bg_bit_allocatable) on a mounted OCFS2 volume, not via network packet processing or physical device attachment.\nAC:L - An unprivileged attacker can drive both sides of the race by running concurrent writers/creators that trigger cluster bitmap searches while forcing journal commits (sync/fsync and heavy metadata activity), so winning the unprotected bh2jh window is attacker-controlled and retryable.\nPR:L - Once OCFS2 is mounted (typical shared-cluster deployment), any unprivileged local user with write permission to files or directories can exercise the allocation path; no CAP_SYS_ADMIN or init-namespace root is required along the vulnerable code path.\nUI:N - The attacker performs the concurrent writes and syncs themselves; no separate victim action such as opening a crafted file or confirming a prompt is required beyond the filesystem already being mounted.\nS:U - Impact is kernel memory corruption / oops within the same host OS authority (OCFS2/JBD2), with no VM escape, IOMMU bypass, or other cross-boundary scope change.\nC:H - Between bh2jh() and use of the journal_head, jbd2 can free the object, creating a use-after-free; per guidance a UAF enables heap reclaim and arbitrary kernel read primitives.\nI:H - The same journal_head UAF (spin_lock and access to b_committed_data on a freed slab object) is exploitable via heap spray for write and control-flow hijacking primitives in the kernel.\nA:H - The observed race already causes a kernel page-fault panic (NULL or dangling journal_head dereference in ocfs2_block_group_find_clear_bits), which is full availability impact even without a complete exploit."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/suballoc.c"],"versions":[{"version":"ccd979bdbce9fba8412beb3f1de68a9d0171b12c","lessThan":"5043fbd294f5909a080ade0f04b70a4da9e122b7","status":"affected","versionType":"git"},{"version":"ccd979bdbce9fba8412beb3f1de68a9d0171b12c","lessThan":"2e382600e8856ea654677b5134ee66e03ea72bc2","status":"affected","versionType":"git"},{"version":"ccd979bdbce9fba8412beb3f1de68a9d0171b12c","lessThan":"6f1b228529ae49b0f85ab89bcdb6c365df401558","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/ocfs2/suballoc.c"],"versions":[{"version":"2.6.16","status":"affected"},{"version":"0","lessThan":"2.6.16","status":"unaffected","versionType":"semver"},{"version":"5.10.77","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.14.16","lessThanOrEqual":"5.14.*","status":"unaffected","versionType":"semver"},{"version":"5.15","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.16","versionEndExcluding":"5.10.77"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.16","versionEndExcluding":"5.14.16"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.16","versionEndExcluding":"5.15"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5043fbd294f5909a080ade0f04b70a4da9e122b7"},{"url":"https://git.kernel.org/stable/c/2e382600e8856ea654677b5134ee66e03ea72bc2"},{"url":"https://git.kernel.org/stable/c/6f1b228529ae49b0f85ab89bcdb6c365df401558"}],"title":"ocfs2: fix race between searching chunks and release journal_head from buffer_head","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-06T18:35:17.607326Z","id":"CVE-2021-47493","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-06T18:35:30.175Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T05:39:59.750Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/5043fbd294f5909a080ade0f04b70a4da9e122b7","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/2e382600e8856ea654677b5134ee66e03ea72bc2","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/6f1b228529ae49b0f85ab89bcdb6c365df401558","tags":["x_transferred"]}]}]}}