CVE-2021-47458·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: ocfs2: mount fails with buffer overflow in strlen Starting with kernel 5.11 built with CONFIG_FORTIFY_SOURCE mouting an ocfs2 filesystem with either o2cb or pcmk cluster stack fails with the trace below. Problem seems to be that strings for cluster stack and cluster name are not guaranteed to be null terminated in the disk representation, while strlcpy assumes that the source string is always null terminated. This causes a read outside of the source string triggering the buffer overflow detection. detected buffer overflow in strlen ------------[ cut here ]------------ kernel BUG at lib/string.c:1149! invalid opcode: 0000 [#1] SMP PTI CPU: 1 PID: 910 Comm: mount.ocfs2 Not tainted 5.14.0-1-amd64 #1 Debian 5.14.6-2 RIP: 0010:fortify_panic+0xf/0x11 ... Call Trace: ocfs2_initialize_super.isra.0.cold+0xc/0x18 [ocfs2] ocfs2_fill_super+0x359/0x19b0 [ocfs2] mount_bdev+0x185/0x1b0 legacy_get_tree+0x27/0x40 vfs_get_tree+0x25/0xb0 path_mount+0x454/0xa20 __x64_sys_mount+0x103/0x140 do_syscall_64+0x3b/0xc0 entry_SYSCALL_64_after_hwframe+0x44/0xae
- Severity
- high
- Software
- Kernel
- Fixed in
- 5.14.15
- Published
- 2024-05-22
Affected versions
From: 5.11
Until: 5.14.15
Fixed in: 5.14.15
How to fix this CVE
Update your Linux kernel to version 5.14.15 or later to fix a buffer overflow vulnerability in OCFS2 filesystem mounting. This vulnerability affects systems running kernel versions 5.11 through 5.14.14 that are compiled with CONFIG_FORTIFY_SOURCE enabled. The issue occurs when mounting OCFS2 filesystems with o2cb or pcmk cluster stacks due to improper null-termination handling of cluster stack and cluster name strings, which can cause kernel panics during mount operations.
sudo dnf update kernelDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version by running: uname -r
- Step 2: Verify if CONFIG_FORTIFY_SOURCE is enabled in your kernel: cat /boot/config-$(uname -r) | grep CONFIG_FORTIFY_SOURCE
- Step 3: Check if OCFS2 is loaded on your system: lsmod | grep ocfs2
- Step 4: Review kernel logs for buffer overflow errors during OCFS2 mount attempts: sudo dmesg | grep -i 'buffer overflow\|ocfs2\|fortify_panic'
- Step 5: Verify the fix by confirming your kernel version is 5.14.15 or later: uname -r | grep -E '5\.1[5-9]|5\.2[0-9]|[6-9]\.[0-9]'
FAQ
What is CVE-2021-47458?
CVE-2021-47458 is a buffer overflow vulnerability in the Linux kernel's OCFS2 filesystem driver that occurs when mounting filesystems with o2cb or pcmk cluster stacks. The vulnerability is triggered because cluster stack and cluster name strings from disk are not properly null-terminated, causing fortified string functions to read beyond allocated buffer boundaries.
Is CVE-2021-47458 being actively exploited?
No, CVE-2021-47458 is not listed as actively exploited in the CISA Known Exploited Vulnerabilities catalog, and no public exploits are known to exist.
What versions of Kernel are affected by CVE-2021-47458?
Linux kernel versions 5.11 through 5.14.14 are affected when compiled with CONFIG_FORTIFY_SOURCE enabled.
How do I check if my server is vulnerable to CVE-2021-47458?
Run: uname -r to check your kernel version (if between 5.11-5.14.14), then verify CONFIG_FORTIFY_SOURCE is enabled with: cat /boot/config-$(uname -r) | grep CONFIG_FORTIFY_SOURCE
Does Defensia detect CVE-2021-47458?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2021-47458 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/0e677ea5b7396f715a76b6b0ef441430e4c4b57f
- https://git.kernel.org/stable/c/232ed9752510de4436468b653d145565669c8498
- https://git.kernel.org/stable/c/4b74ddcc22ee6455946e80a9c4808801f8f8561e
- https://git.kernel.org/stable/c/7623b1035ca2d17bde0f6a086ad6844a34648df1
- https://git.kernel.org/stable/c/93be0eeea14cf39235e585c8f56df3b3859deaad
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2021-47458. Free for 1 server.
Get started free