Skip to content

kernel CVE-2021-40490

Moderate
cbgbt published GHSA-ff7c-gq5h-m6rj Nov 13, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.4.0

Patched versions

1.4.0

Description

A race condition was discovered in the ext4 subsystem writing to an inline_data file while its extended attributes are changing. The issue applies only if inline_data is enabled for the ext4 partition, and by default it is disabled.

Severity

Moderate

CVE ID

CVE-2021-40490

Weaknesses

No CWEs