CVE-2021-46950

HIGH

Linux kernel 4.14.147-4.14.233 - Data Corruption via RAID1 Write Request Failure Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: md/raid1: properly indicate failure when ending a failed write request This patch addresses a data corruption bug in raid1 arrays using bitmaps. Without this fix, the bitmap bits for the failed I/O end up being cleared. Since we are in the failure leg of raid1_end_write_request, the request either needs to be retried (R1BIO_WriteError) or failed (R1BIO_Degraded).

Scores

CVSS v3 7.8
EPSS 0.0025
EPSS Percentile 16.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (23)
Linux/Linux < 5.4
Linux/Linux 1cd972e0a10760a1fa27d9830d78446c891c23b6 - a6e17cab00fc5bf85472434c52ac751426257c6f
Linux/Linux 344242d50f468a250bf4b6136934392758412ed8
Linux/Linux 4.14.147 - 4.14.233
Linux/Linux 4.14.233 - 4.14.*
Linux/Linux 4.19.191 - 4.19.*
Linux/Linux 4.19.77 - 4.19.191
Linux/Linux 5.10.36 - 5.10.*
Linux/Linux 5.11.20 - 5.11.*
Linux/Linux 5.12.3 - 5.12.*
... and 13 more
Published Feb 27, 2024
Tracked Since Feb 18, 2026