LiveActive security incident?Get immediate response
CVE Record

CVE-2021-47335: f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances As syzbot reported, there is an use-after-free issue during f2fs recovery: Use-after-free write at 0xffff88823bc16040 (in kfence-#10): kmem_cache_destroy+0x1f/0x120 mm/slab_common.c:486 f2fs_recover_fsync_data+0x75b0/0x8380 fs/f2fs/recovery.c:869 f2fs_fill_super+0x9393/0xa420 fs/f2fs/super.c:3945 mount_bdev+0x26c/0x3a0 fs/super.c:1367 legacy_get_tree+0xea/0x180 fs/fs_context.c:592 vfs_get_tree+0x86/0x270 fs/super.c:1497 do_new_mount fs/namespace.c:2905 [inline] path_mount+0x196f/0x2be0 fs/namespace.c:3235 do_mount fs/namespace.c:3248 [inline] __do_sys_mount fs/namespace.c:3456 [inline] __se_sys_mount+0x2f9/0x3b0 fs/namespace.c:3433 do_syscall_64+0x3f/0xb0 arch/x86/entry/common.c:47 entry_SYSCALL_64_after_hwframe+0x44/0xae The root cause is multi f2fs filesystem instances can race on accessing global fsync_entry_slab pointer, result in use-after-free issue of slab cache, fixes to init/destroy this slab cache only once during module init/destroy procedure to avoid this issue.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2021-47335 is a Linux kernel F2FS filesystem bug. Multiple F2FS filesystem instances can race over a shared slab-cache pointer during recovery, causing a use-after-free write. The sources do not provide CVSS, confirmed exploitation, or business-impact scoring, so urgency depends on whether affected Linux kernels and F2FS are used.

Executive priority

Treat this as a targeted Linux kernel maintenance issue unless F2FS is used in production or embedded fleets. Ask operations to confirm exposure and align patching with normal kernel update cycles unless vendor guidance raises severity.

Technical view

The flaw is in Linux F2FS recovery around fsync_entry_slab lifecycle handling. A global fsync_entry_slab pointer could be initialized or destroyed unsafely across multiple F2FS instances, leading to use-after-free during f2fs_recover_fsync_data. The kernel fix moves slab cache init/destroy to module init/destroy so it happens once.

Likely exposure

Exposure appears limited to Linux systems running affected kernel versions where F2FS is enabled and mounted, especially recovery paths involving multiple F2FS filesystem instances. The source bundle does not identify affected distributions, cloud images, appliances, or default configurations.

Exploitation context

The record cites a syzbot-reported use-after-free and marks KEV as false. No provided source states active exploitation, public weaponization, remote reachability, required privileges, or exploit reliability.

Researcher notes

Evidence supports a kernel use-after-free in F2FS recovery caused by cross-instance slab-cache lifecycle racing. Key unknowns are exploitability, privilege requirements, affected distro backports, and whether F2FS is reachable in specific deployments.

Mitigation direction

  • Check Linux vendor advisories for a kernel containing the referenced stable fixes.
  • Prioritize updates where F2FS is enabled or operationally required.
  • Confirm distribution backports rather than relying only on upstream version numbers.
  • Avoid exposing unpatched systems to untrusted F2FS media where feasible.

Validation and detection

  • Inventory Linux kernel versions across servers, endpoints, and embedded systems.
  • Identify systems with F2FS support enabled or F2FS filesystems mounted.
  • Map installed kernels to vendor advisories or the referenced stable commits.
  • Document systems where F2FS is unused as lower exposure, not automatically unaffected.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-47335 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
5Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux98e4da8ca301e062d79ae168c67e56f3c3de3ce4, 98e4da8ca301e062d79ae168c67e56f3c3de3ce4, 98e4da8ca301e062d79ae168c67e56f3c3de3ce4, 98e4da8ca301e062d79ae168c67e56f3c3de3ce4unaffected
LinuxLinux3.8, 0, 5.10.51, 5.12.18, 5.13.3, 5.14affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.