Action not permitted
Modal body text goes here.
Modal Title
Modal Body
EUVD-2026-344458
European Vulnerability Database identifier assigned by ENISAReserved
2026-10-02 07:56
Assigner
ENISA
Alias of
a CVE record, shown under related vulnerabilities.
This identifier carries no description, severity or references of its own:
they belong to that CVE.
{
"assigner": "ENISA",
"date_reserved": "2026-10-02T07:56:15.442537+00:00",
"id": "EUVD-2026-344458"
}
CVE-2021-47343 (GCVE-0-2021-47343)
Vulnerability from cvelistv5 – Published: 2024-05-21 14:35 – Updated: 2026-08-05 08:47
VLAI
EPSS
VEX
Title
dm btree remove: assign new_root only when removal succeeds
Summary
In the Linux kernel, the following vulnerability has been resolved:
dm btree remove: assign new_root only when removal succeeds
remove_raw() in dm_btree_remove() may fail due to IO read error
(e.g. read the content of origin block fails during shadowing),
and the value of shadow_spine::root is uninitialized, but
the uninitialized value is still assign to new_root in the
end of dm_btree_remove().
For dm-thin, the value of pmd->details_root or pmd->root will become
an uninitialized value, so if trying to read details_info tree again
out-of-bound memory may occur as showed below:
general protection fault, probably for non-canonical address 0x3fdcb14c8d7520
CPU: 4 PID: 515 Comm: dmsetup Not tainted 5.13.0-rc6
Hardware name: QEMU Standard PC
RIP: 0010:metadata_ll_load_ie+0x14/0x30
Call Trace:
sm_metadata_count_is_more_than_one+0xb9/0xe0
dm_tm_shadow_block+0x52/0x1c0
shadow_step+0x59/0xf0
remove_raw+0xb2/0x170
dm_btree_remove+0xf4/0x1c0
dm_pool_delete_thin_device+0xc3/0x140
pool_message+0x218/0x2b0
target_message+0x251/0x290
ctl_ioctl+0x1c4/0x4d0
dm_ctl_ioctl+0xe/0x20
__x64_sys_ioctl+0x7b/0xb0
do_syscall_64+0x40/0xb0
entry_SYSCALL_64_after_hwframe+0x44/0xae
Fixing it by only assign new_root when removal succeeds
Severity
7.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-05-23 19:04 UTC
Assigner
References
9 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 , < 4c84b3e0728ffe10d89c633694c35a02b5c477dc
(git)
Affected: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 , < c154775619186781aaf8a99333ac07437a1768d5 (git) Affected: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 , < 73f27adaa73e3057a9ec464e33c4f54d34ea5de3 (git) Affected: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 , < 8fbae4a1bdb5b889490cdee929e68540151536e5 (git) Affected: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 , < 964d57d1962d7e68f0f578f05d9ae4a104d74851 (git) Affected: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 , < ba47e65a5de3e0e8270301a409fc63d3129fdb9e (git) Affected: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 , < 89bf942314b78d454db92427201421b5dec132d9 (git) Affected: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 , < ad365e9351ac2b450e7e79932ff6abf59342d91a (git) Affected: 3241b1d3e0aaafbfcd320f4d71ade629728cc4f4 , < b6e58b5466b2959f83034bead2e2e1395cca8aeb (git) |
|
| Linux | Linux |
Affected:
3.2
Unaffected: 0 , < 3.2 (semver) Unaffected: 4.4.276 , ≤ 4.4.* (semver) Unaffected: 4.9.276 , ≤ 4.9.* (semver) Unaffected: 4.14.240 , ≤ 4.14.* (semver) Unaffected: 4.19.198 , ≤ 4.19.* (semver) Unaffected: 5.4.133 , ≤ 5.4.* (semver) Unaffected: 5.10.51 , ≤ 5.10.* (semver) Unaffected: 5.12.18 , ≤ 5.12.* (semver) Unaffected: 5.13.3 , ≤ 5.13.* (semver) Unaffected: 5.14 , ≤ * (original_commit_for_fix) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2021-47343",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-23T19:04:19.383705Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-06-04T17:15:19.329Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-04T05:32:08.519Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/4c84b3e0728ffe10d89c633694c35a02b5c477dc"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/c154775619186781aaf8a99333ac07437a1768d5"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/73f27adaa73e3057a9ec464e33c4f54d34ea5de3"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/8fbae4a1bdb5b889490cdee929e68540151536e5"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/964d57d1962d7e68f0f578f05d9ae4a104d74851"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/ba47e65a5de3e0e8270301a409fc63d3129fdb9e"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/89bf942314b78d454db92427201421b5dec132d9"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/ad365e9351ac2b450e7e79932ff6abf59342d91a"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.kernel.org/stable/c/b6e58b5466b2959f83034bead2e2e1395cca8aeb"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/md/persistent-data/dm-btree-remove.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4c84b3e0728ffe10d89c633694c35a02b5c477dc",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "c154775619186781aaf8a99333ac07437a1768d5",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "73f27adaa73e3057a9ec464e33c4f54d34ea5de3",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "8fbae4a1bdb5b889490cdee929e68540151536e5",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "964d57d1962d7e68f0f578f05d9ae4a104d74851",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "ba47e65a5de3e0e8270301a409fc63d3129fdb9e",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "89bf942314b78d454db92427201421b5dec132d9",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "ad365e9351ac2b450e7e79932ff6abf59342d91a",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
},
{
"lessThan": "b6e58b5466b2959f83034bead2e2e1395cca8aeb",
"status": "affected",
"version": "3241b1d3e0aaafbfcd320f4d71ade629728cc4f4",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/md/persistent-data/dm-btree-remove.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"lessThan": "3.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.4.*",
"status": "unaffected",
"version": "4.4.276",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.9.*",
"status": "unaffected",
"version": "4.9.276",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.14.*",
"status": "unaffected",
"version": "4.14.240",
"versionType": "semver"
},
{
"lessThanOrEqual": "4.19.*",
"status": "unaffected",
"version": "4.19.198",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.4.*",
"status": "unaffected",
"version": "5.4.133",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.51",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.12.*",
"status": "unaffected",
"version": "5.12.18",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.13.*",
"status": "unaffected",
"version": "5.13.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "5.14",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.4.276",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.9.276",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.14.240",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.19.198",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.4.133",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.51",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.12.18",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.13.3",
"versionStartIncluding": "3.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.14",
"versionStartIncluding": "3.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm btree remove: assign new_root only when removal succeeds\n\nremove_raw() in dm_btree_remove() may fail due to IO read error\n(e.g. read the content of origin block fails during shadowing),\nand the value of shadow_spine::root is uninitialized, but\nthe uninitialized value is still assign to new_root in the\nend of dm_btree_remove().\n\nFor dm-thin, the value of pmd-\u003edetails_root or pmd-\u003eroot will become\nan uninitialized value, so if trying to read details_info tree again\nout-of-bound memory may occur as showed below:\n\n general protection fault, probably for non-canonical address 0x3fdcb14c8d7520\n CPU: 4 PID: 515 Comm: dmsetup Not tainted 5.13.0-rc6\n Hardware name: QEMU Standard PC\n RIP: 0010:metadata_ll_load_ie+0x14/0x30\n Call Trace:\n sm_metadata_count_is_more_than_one+0xb9/0xe0\n dm_tm_shadow_block+0x52/0x1c0\n shadow_step+0x59/0xf0\n remove_raw+0xb2/0x170\n dm_btree_remove+0xf4/0x1c0\n dm_pool_delete_thin_device+0xc3/0x140\n pool_message+0x218/0x2b0\n target_message+0x251/0x290\n ctl_ioctl+0x1c4/0x4d0\n dm_ctl_ioctl+0xe/0x20\n __x64_sys_ioctl+0x7b/0xb0\n do_syscall_64+0x40/0xb0\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nFixing it by only assign new_root when removal succeeds"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The vulnerable path is reached only through local device-mapper operations\u2014dmsetup ioctls on /dev/mapper/control (pool message \u2192 delete/create) or local block I/O/discard on a dm-thin volume that calls dm_thin_remove_range \u2192 dm_btree_remove\u2014not via network packet processing.\nAC:L - An attacker can reliably force the first shadow_step to fail (leaving spine.root uninitialized) by exhausting metadata space so dm_sm_new_block returns -ENOSPC during discard/remove, or\u2014on the admin path\u2014by placing dm-flakey under the metadata device; neither depends on a race or layout outside attacker influence.\nPR:L - Although the dmsetup path requires capable(CAP_SYS_ADMIN), dm_btree_remove is also reachable from unprivileged discard/write I/O on a thin volume via dm_thin_remove_range/__remove_range with no capability check, which is the common cloud/container deployment of dm-thin.\nUI:N - The attacker issues the discard, writes that fill metadata, or dmsetup delete themselves; no separate victim action such as mounting a crafted filesystem is required.\nS:U - Corruption and the resulting oops remain inside the host kernel\u2019s dm-thin/persistent-data authority and do not cross a VM, IOMMU, or other security boundary.\nC:H - The uninitialized new_root is later used as a metadata block number; at the time of the bug sm_ll_lookup_bitmap had no bounds check, so metadata_ll_load_ie performs an unbounded out-of-bounds read of kernel memory (as the commit\u2019s non-canonical GPF demonstrates), which per guidance scores Confidentiality High.\nI:H - The same unbounded index path exists in metadata_ll_save_ie (OOB write), and installing attacker-influenceable stack garbage as pmd-\u003eroot/details_root causes subsequent btree shadowing/updates to read and write metadata through a corrupted root\u2014memory-corruption integrity impact High under the stated guidance.\nA:H - The documented consequence is a general protection fault / kernel oops when the corrupted root is reused (metadata_ll_load_ie GPF in the commit), which is a complete availability loss."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T08:47:20.543Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4c84b3e0728ffe10d89c633694c35a02b5c477dc"
},
{
"url": "https://git.kernel.org/stable/c/c154775619186781aaf8a99333ac07437a1768d5"
},
{
"url": "https://git.kernel.org/stable/c/73f27adaa73e3057a9ec464e33c4f54d34ea5de3"
},
{
"url": "https://git.kernel.org/stable/c/8fbae4a1bdb5b889490cdee929e68540151536e5"
},
{
"url": "https://git.kernel.org/stable/c/964d57d1962d7e68f0f578f05d9ae4a104d74851"
},
{
"url": "https://git.kernel.org/stable/c/ba47e65a5de3e0e8270301a409fc63d3129fdb9e"
},
{
"url": "https://git.kernel.org/stable/c/89bf942314b78d454db92427201421b5dec132d9"
},
{
"url": "https://git.kernel.org/stable/c/ad365e9351ac2b450e7e79932ff6abf59342d91a"
},
{
"url": "https://git.kernel.org/stable/c/b6e58b5466b2959f83034bead2e2e1395cca8aeb"
}
],
"title": "dm btree remove: assign new_root only when removal succeeds",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2021-47343",
"datePublished": "2024-05-21T14:35:50.293Z",
"dateReserved": "2024-05-21T14:28:16.979Z",
"dateUpdated": "2026-08-05T08:47:20.543Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…