Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2021-47335
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2021-47335 is a vulnerability in the Linux kernel's F2FS (Flash-Friendly File System) that involves a use-after-free issue during filesystem recovery. The vulnerability was discovered and reported by syzbot, and was resolved in May 2021. The issue affects the F2FS filesystem implementation when multiple filesystem instances are present (NVD).

Technical details

The vulnerability occurs when multiple F2FS filesystem instances race on accessing the global fsync_entry_slab pointer, resulting in a use-after-free issue of the slab cache. The issue manifests during F2FS recovery operations, specifically in the kmem_cache_destroy function at mm/slab_common.c:486. The bug is triggered through the call chain: f2fs_recover_fsync_data -> f2fs_fill_super -> mount_bdev -> legacy_get_tree -> vfs_get_tree -> do_new_mount (Kernel Commit).

Impact

The vulnerability could lead to use-after-free conditions in the kernel, potentially resulting in system crashes, memory corruption, or privilege escalation. The issue affects systems using the F2FS filesystem with multiple filesystem instances (NVD).

Exploitability

The vulnerability requires local access to a system using F2FS filesystem and the ability to mount multiple F2FS filesystem instances. No public exploits have been reported in the wild (NVD).

Mitigation and workarounds

The issue has been fixed by modifying the initialization and destruction of the slab cache to occur only once during module init/destroy procedure. The fix involves changes to multiple F2FS-related files including f2fs.h, recovery.c, and super.c. Users should update their Linux kernel to a version containing the fix (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-aws-7.0
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-aws-7.0
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-hwe-6.17
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-nvidia-6.14
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-7.0
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management