SB2021080819 - Improper locking in Linux kernel
Published: August 8, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2021-38203)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.
Remediation
Install update from vendor's website.