CVE-2021-47066

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 29, 2024
Updated: Jan 9, 2025

Summary

CVE-2021-47066 is a vulnerability affecting the Linux kernel's async_xor function. In RMW (Rewrite Merge Write) mode, a correction in the handling of source offsets during parity checks has resulted in incorrect xor value calculations. This issue can lead to data corruption, specifically during the creation and formatting of MD RAID arrays on POWER8 machines. A successful exploit involves creating and mounting an XFS file system on a RAID device, resulting in a system call failure during the mount process.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share