🛡️ UBUNTU-CVE-2021-47508
⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: free exchange changeset on failures Fstests runs on my VMs have show several kmemleak reports like the following. unreferenced object 0xffff88811ae59080 (size 64): comm "xfs_io", pid 12124, jiffies 4294987392 (age 6.368s) hex dump (first 32 bytes): 00 c0 1c 00 00 00 00 00 ff cf 1c 00 00 00 00 00 ................ 90 97 e5 1a 81 88 ff ff 90 97 e5 1a 81 88 ff ff ................ backtrace: [] ulist_add_merge+0x60/0x150 [btrfs] [] set_state_bits+0x86/0xc0 [btrfs] [] set_extent_bit+0x270/0x690 [btrfs] [] set_record_extent_bits+0x19/0x20 [btrfs] [] qgroup_reserve_data+0x274/0x310 [btrfs] [] btrfs_check_data_free_space+0x5c/0xa0 [btrfs] [] btrfs_delalloc_reserve_space+0x1b/0xa0 [btrfs] [] btrfs_dio_iomap_begin+0x415/0x970 [btrfs] [] iomap_iter+0x161/0x1e0 [] __iomap_dio_rw+0x1df/0x700 [] iomap_dio_rw+0x5/0x20 [] btrfs_file_write_iter+0x290/0x530 [btrfs] [] new_sync_write+0x106/0x180 [] vfs_write+0x24d/0x2f0 [] __x64_sys_pwrite64+0x69/0xa0 [] do_syscall_64+0x43/0x90 In case brtfs_qgroup_reserve_data() or btrfs_delalloc_reserve_metadata() fail the allocated extent_changeset will not be freed. So in btrfs_check_data_free_space() and btrfs_delalloc_reserve_space() free the allocated extent_changeset to get rid of the allocated memory. The issue currently only happens in the direct IO write path, but only after 65b3c08606e5 ("btrfs: fix ENOSPC failure when attempting direct IO write into NOCOW range"), and also at defrag_one_locked_target(). Every other place is always calling extent_changeset_free() even if its call to btrfs_delalloc_reserve_space() or btrfs_check_data_free_space() has failed.

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-05-24
Updated 2026-06-09
Modified 2026-06-08
Fix URL N/A

Affected Packages

Software From version Fixed in
linux
linux-allwinner-5.19
linux-aws
linux-aws-5.0
linux-aws-5.11
linux-aws-5.13
linux-aws-5.19
linux-aws-5.3
linux-aws-5.4
linux-aws-5.8
linux-aws-6.2
linux-aws-fips
linux-aws-hwe
linux-azure
linux-azure-4.15
linux-azure-5.11
linux-azure-5.13
linux-azure-5.19
linux-azure-5.3
linux-azure-5.4
linux-azure-5.8
linux-azure-6.2
linux-azure-edge
linux-azure-fde
linux-azure-fde-5.15
linux-azure-fde-5.19
linux-azure-fde-6.2
linux-azure-fips
linux-bluefield
linux-fips
linux-gcp
linux-gcp-4.15
linux-gcp-5.11
linux-gcp-5.13
linux-gcp-5.19
linux-gcp-5.3
linux-gcp-5.4
linux-gcp-5.8
linux-gcp-6.2
linux-gcp-fips
linux-gke
linux-gke-4.15
linux-gke-5.15
linux-gke-5.4
linux-gkeop
linux-gkeop-5.4
linux-hwe
linux-hwe-5.11
linux-hwe-5.13
linux-hwe-5.19
linux-hwe-5.4
linux-hwe-5.8
linux-hwe-6.2
linux-hwe-edge
linux-ibm
linux-ibm-5.4
linux-intel-5.13
linux-intel-iot-realtime
linux-iot
linux-kvm
linux-lowlatency-hwe-5.19
linux-lowlatency-hwe-6.2
linux-lts-xenial
linux-nvidia
linux-nvidia-6.2
linux-oem
linux-oem-5.10
linux-oem-5.13
linux-oem-5.14
linux-oem-5.17
linux-oem-5.6
linux-oem-6.0
linux-oem-6.1
linux-oracle
linux-oracle-5.0
linux-oracle-5.11
linux-oracle-5.13
linux-oracle-5.3
linux-oracle-5.4
linux-oracle-5.8
linux-raspi
linux-raspi-5.4
linux-raspi-realtime
linux-raspi2
linux-realtime
linux-riscv
linux-riscv-5.11
linux-riscv-5.19
linux-riscv-5.8
linux-starfive-5.19
linux-starfive-6.2
linux-xilinx-zynqmp

Similar Threats

Site Security Check

Concerned your site may already be targeted?

BotEraser analyzes incoming traffic patterns and helps identify bot behavior consistent with known exploit attempts.

Check My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.