CVE-2021-45868: Use After Free
In the Linux kernel before 5.15.3, fs/quota/quotatree.c does not validate the block number in the quota tree (on disk). This can, for example, lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-45868?
CVE-2021-45868 has a high severity due to its potential to cause a use-after-free vulnerability in the Linux kernel.
How do I fix CVE-2021-45868?
To fix CVE-2021-45868, update to the following Linux kernel versions: 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.13-1.
Which versions of the Linux kernel are affected by CVE-2021-45868?
CVE-2021-45868 affects the Linux kernel versions earlier than 5.15.3.
What types of systems are impacted by CVE-2021-45868?
CVE-2021-45868 primarily impacts systems running the Linux kernel prior to version 5.15.3.
Is there any workaround for CVE-2021-45868?
There is no specific workaround for CVE-2021-45868; the recommended action is to apply the relevant updates to the kernel.