CVE-2021-47335: f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances
As syzbot reported, there is an use-after-free issue during f2fs recovery:
Use-after-free write at 0xffff88823bc16040 (in kfence-#10):
kmem_cache_destroy+0x1f/0x120 mm/slab_common.c:486
f2fs_recover_fsync_data+0x75b0/0x8380 fs/f2fs/recovery.c:869
f2fs_fill_super+0x9393/0xa420 fs/f2fs/super.c:3945
mount_bdev+0x26c/0x3a0 fs/super.c:1367
legacy_get_tree+0xea/0x180 fs/fs_context.c:592
vfs_get_tree+0x86/0x270 fs/super.c:1497
do_new_mount fs/namespace.c:2905 [inline]
path_mount+0x196f/0x2be0 fs/namespace.c:3235
do_mount fs/namespace.c:3248 [inline]
__do_sys_mount fs/namespace.c:3456 [inline]
__se_sys_mount+0x2f9/0x3b0 fs/namespace.c:3433
do_syscall_64+0x3f/0xb0 arch/x86/entry/common.c:47
entry_SYSCALL_64_after_hwframe+0x44/0xae
The root cause is multi f2fs filesystem instances can race on accessing
global fsync_entry_slab pointer, result in use-after-free issue of slab
cache, fixes to init/destroy this slab cache only once during module
init/destroy procedure to avoid this issue.
Security readout for executives and security teams
Plain-English summary
CVE-2021-47335 is a Linux kernel F2FS filesystem bug. Multiple F2FS filesystem instances can race over a shared slab-cache pointer during recovery, causing a use-after-free write. The sources do not provide CVSS, confirmed exploitation, or business-impact scoring, so urgency depends on whether affected Linux kernels and F2FS are used.
Executive priority
Treat this as a targeted Linux kernel maintenance issue unless F2FS is used in production or embedded fleets. Ask operations to confirm exposure and align patching with normal kernel update cycles unless vendor guidance raises severity.
Technical view
The flaw is in Linux F2FS recovery around fsync_entry_slab lifecycle handling. A global fsync_entry_slab pointer could be initialized or destroyed unsafely across multiple F2FS instances, leading to use-after-free during f2fs_recover_fsync_data. The kernel fix moves slab cache init/destroy to module init/destroy so it happens once.
Likely exposure
Exposure appears limited to Linux systems running affected kernel versions where F2FS is enabled and mounted, especially recovery paths involving multiple F2FS filesystem instances. The source bundle does not identify affected distributions, cloud images, appliances, or default configurations.
Exploitation context
The record cites a syzbot-reported use-after-free and marks KEV as false. No provided source states active exploitation, public weaponization, remote reachability, required privileges, or exploit reliability.
Researcher notes
Evidence supports a kernel use-after-free in F2FS recovery caused by cross-instance slab-cache lifecycle racing. Key unknowns are exploitability, privilege requirements, affected distro backports, and whether F2FS is reachable in specific deployments.
Mitigation direction
Check Linux vendor advisories for a kernel containing the referenced stable fixes.
Prioritize updates where F2FS is enabled or operationally required.
Confirm distribution backports rather than relying only on upstream version numbers.
Avoid exposing unpatched systems to untrusted F2FS media where feasible.
Validation and detection
Inventory Linux kernel versions across servers, endpoints, and embedded systems.
Identify systems with F2FS support enabled or F2FS filesystems mounted.
Map installed kernels to vendor advisories or the referenced stable commits.
Document systems where F2FS is unused as lower exposure, not automatically unaffected.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2021-47335 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.