Kernel crash via stale EXT4 inline-data state
Published Jan 18, 2024 · Updated Feb 13, 2025
Integer overflow in the EXT4 filesystem of openEuler Kernel allows local users to crash affected systems through crafted inline-data writes. ext4_write_end checks for inline data but fails to verify the EXT4_STATE_MAY_INLINE_DATA flag before calling ext4_write_inline_data_end, triggering a kernel BUG after inline-data conversion begins. The issue affects the 4.19.90 line before 4.19.90-2401.3 and the 5.10.0-60.18.0 line before 5.10.0-183.0.0; exploitation requires local low-privileged access.
Summary
What happened
Integer overflow in the EXT4 filesystem of openEuler Kernel allows local users to crash affected systems through crafted inline-data writes. ext4_write_end checks for inline data but fails to verify the EXT4_STATE_MAY_INLINE_DATA flag before calling ext4_write_inline_data_end, triggering a kernel BUG after inline-data conversion begins. The issue affects the 4.19.90 line before 4.19.90-2401.3 and the 5.10.0-60.18.0 line before 5.10.0-183.0.0; exploitation requires local low-privileged access.
The record
- CVE
- CVE-2021-33631
- Published
- Jan 18, 2024
- Updated
- Feb 13, 2025
- Vendor
- openEuler
- Product
- openEuler Kernel
- Classifications
- CWE-190, CAPEC-92, T1499.004
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Jan 18, 2024CVE publishedPublication date reported by the CVE source.
- Feb 13, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=4.19.90 <4.19.90-2401.3 changes=[{"at":"cf1d16ea2f1086c0765348344b70aa2361436642 ext4: fix kernel BUG in 'ext4_write_inline_data_end()'","status":"unaffected"}]
- Affected versionversion=5.10.0-60.18.0 <5.10.0-183.0.0 changes=[{"at":"1587126a0f2a79b3ee6cb309bbfaf079c39eda29 ext4: fix kernel BUG in 'ext4_write_inline_data_end()'","status":"unaffected"}]
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo