7.0highHigh
CVE-2021-40490
Netapp Solidfire Baseboard Management Controller
A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is requires local access to the machine.
- For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
- To exploit it, an ordinary user account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.0 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H- Weakness
- CWE-362
- Assigned by
- cve@mitre.org
Dates
- Published
- 2021-09-03
- Last modified
- 2026-08-13
- Sources
- NVD
Affected products
- Netapp Solidfire Baseboard Management Controllerall versions
- Linux Linux Kernel3.8 - 4.4.284, 4.5 - 4.9.283, 4.10 - 4.14.247, 4.15 - 4.19.207, 4.20 - 5.4.145, 5.5 - 5.10.63, 5.11 - 5.13.15, 5.14 - 5.14.2
- Fedoraproject Fedora33, 34
- Debian Debian Linux9.0, 11.0
- Netapp Aff A250 Firmwareall versions
- Netapp Aff A250all versions
- Netapp Fas 500f Firmwareall versions
- Netapp Fas 500fall versions
- Netapp H300s Firmwareall versions
- Netapp H300sall versions
- Netapp H500s Firmwareall versions
- Netapp H500sall versions
As listed in the NVD configuration data. Not a statement about your estate.
References
- https://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4.git/commit/?id=9e445093e523f3277081314c864f708fd4bd34aa
- https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html
- https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M6VS2DLGT7TK7URKAS2KWJL3S533SGVA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XJGX3DMJT6MRBW2XEF3TWVHYWZW3DG3N/
- https://security.netapp.com/advisory/ntap-20211004-0001/
- https://www.debian.org/security/2021/dsa-4978
- https://git.kernel.org/pub/scm/linux/kernel/git/tytso/ext4.git/commit/?id=9e445093e523f3277081314c864f708fd4bd34aa
- https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html
- https://lists.debian.org/debian-lts-announce/2021/12/msg00012.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M6VS2DLGT7TK7URKAS2KWJL3S533SGVA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XJGX3DMJT6MRBW2XEF3TWVHYWZW3DG3N/
- https://security.netapp.com/advisory/ntap-20211004-0001/
- https://www.debian.org/security/2021/dsa-4978