7.0highHigh

CVE-2021-40490

Netapp Solidfire Baseboard Management Controller

A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
7.0 (v3.1)
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-362
Assigned by
cve@mitre.org

Dates

Published
2021-09-03
Last modified
2026-08-13
Sources
NVD

Affected products

  • Netapp Solidfire Baseboard Management Controllerall versions
  • Linux Linux Kernel3.8 - 4.4.284, 4.5 - 4.9.283, 4.10 - 4.14.247, 4.15 - 4.19.207, 4.20 - 5.4.145, 5.5 - 5.10.63, 5.11 - 5.13.15, 5.14 - 5.14.2
  • Fedoraproject Fedora33, 34
  • Debian Debian Linux9.0, 11.0
  • Netapp Aff A250 Firmwareall versions
  • Netapp Aff A250all versions
  • Netapp Fas 500f Firmwareall versions
  • Netapp Fas 500fall versions
  • Netapp H300s Firmwareall versions
  • Netapp H300sall versions
  • Netapp H500s Firmwareall versions
  • Netapp H500sall versions

As listed in the NVD configuration data. Not a statement about your estate.

References