Lucene search

K
redhatcveRedhat.comRH:CVE-2021-47577
HistoryJun 20, 2024 - 11:25 a.m.

CVE-2021-47577

2024-06-2011:25:31
redhat.com
access.redhat.com
10
linux kernel
io-wq vulnerability
cve-2021-47577

AI Score

9

Confidence

High

In the Linux kernel, the following vulnerability has been resolved: io-wq: check for wq exit after adding new worker task_work We check IO_WQ_BIT_EXIT before attempting to create a new worker, and wq exit cancels pending work if we have any. But it’s possible to have a race between the two, where creation checks exit finding it not set, but we’re in the process of exiting. The exit side will cancel pending creation task_work, but there’s a gap where we add task_work after we’ve canceled existing creations at exit time. Fix this by checking the EXIT bit post adding the creation task_work. If it’s set, run the same cancelation that exit does.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

AI Score

9

Confidence

High