CVE-2021-4023
low
CVSS v3
—
CVSS v2
—
VIR risk
2.5
Description
A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a shortage of free space. This flaw allows a local user with permissions to execute io-uring requests to possibly crash the system.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-4023
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-4023.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 5.15.2-1 | |
| sles | affected | | |
| debian | bookworm | fixed | 5.15.3-1 |
| debian | bullseye | affected | |
| debian | forky | fixed | 5.15.3-1 |
| debian | sid | fixed | 5.15.3-1 |
| debian | trixie | fixed | 5.15.3-1 |
References
Verify integrity in audit chain (admin only). AS-IS.