CVE-2021-47343
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2021-47343 is a vulnerability in the Linux kernel's device mapper (dm) btree removal functionality. The issue was discovered in May 2024 and affects the dm_btree_remove() function. The vulnerability occurs when remove_raw() fails due to IO read errors during block shadowing, causing an uninitialized shadow_spine::root value to be assigned to new_root (NVD).

Technical details

The vulnerability exists in the dm_btree_remove() function where an uninitialized value from shadow_spine::root is assigned to new_root even when the removal operation fails. For dm-thin, this results in pmd->details_root or pmd->root receiving an uninitialized value. When attempting to read the details_info tree subsequently, out-of-bound memory access occurs, leading to a general protection fault with non-canonical addresses (Kernel Patch).

Impact

When exploited, this vulnerability can cause out-of-bound memory access in the Linux kernel, potentially leading to system crashes through general protection faults. The issue specifically affects the device mapper's thin provisioning functionality, which could impact storage management operations (NVD).

Exploitability

The vulnerability can be triggered during normal system operations when there are IO read errors during block shadowing operations in the device mapper. The issue manifests particularly when attempting to delete thin devices, as demonstrated by the crash occurring during dmsetup operations (Kernel Patch).

Mitigation and workarounds

The issue has been fixed by modifying the dm_btree_remove() function to only assign new_root when the removal operation succeeds. The fix involves adding a conditional check before assigning the shadow_root value (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74573CRITICAL9.3
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesAug 15, 2026
CVE-2026-74562HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesAug 15, 2026
CVE-2026-74565HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-uki-virt
NoYesAug 15, 2026
CVE-2026-74578HIGH7.1
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra
NoYesAug 16, 2026
CVE-2026-74579NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-xilinx-zynqmp
NoYesAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management