CVE-2021-45469: High severity Linux Linux kernel vulnerability
In f2fssetxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
Event History
Frequently Asked Questions
What is the severity of CVE-2021-45469?
CVE-2021-45469 is considered a high-severity vulnerability due to its potential to cause out-of-bounds memory access.
How do I fix CVE-2021-45469?
To fix CVE-2021-45469, update your Linux kernel to a version higher than 5.15.11 with patched releases.
Which Linux kernels are affected by CVE-2021-45469?
CVE-2021-45469 affects Linux kernel versions up to and including 5.15.11.
What is the nature of the vulnerability CVE-2021-45469?
CVE-2021-45469 involves an out-of-bounds memory access caused by an invalid last xattr entry in the f2fs file system.
Can CVE-2021-45469 be exploited remotely?
Yes, CVE-2021-45469 can potentially be exploited remotely if an attacker can manipulate inodes to trigger the vulnerability.