CVE-2021-47599
Linux Kernel vulnerability analysis and mitigation

Overview

In the Linux kernel, a vulnerability was identified and resolved in the BTRFS filesystem component, specifically related to the btrfsshowdevname function. The issue was discovered when the test case btrfs/238 reported warnings during device name display operations in the filesystem (Kernel Commit).

Technical details

The vulnerability occurs when btrfspreparesprout() moves the fsdevices::devices into fsdevices::seedlist, causing btrfsshow_devname() to search for devices and find none, which leads to warning messages. The issue specifically affects the device name display functionality in /proc/self/mounts (Kernel Commit).

Impact

The vulnerability could potentially cause system warnings and incorrect device name display in the BTRFS filesystem, affecting system monitoring and filesystem operations (Kernel Commit).

Mitigation and workarounds

The issue has been fixed by updating the code to use latest_dev pointer, which is always valid as it's assigned before device deletion from the list in remove or replace operations. The RCU protection ensures the device structure remains valid until after synchronization (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40258HIGH7
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-devel-matched
NoNoDec 04, 2025
CVE-2025-40259MEDIUM6.2
  • Linux KernelLinux Kernel
  • kernel-64k-devel
NoNoDec 04, 2025
CVE-2025-40264MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoNoDec 04, 2025
CVE-2025-40254MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-modules-partner
NoNoDec 04, 2025
CVE-2025-40253MEDIUM5.5
  • Linux KernelLinux Kernel
  • python3-perf
NoNoDec 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management