{"id":"DEBIAN-CVE-2021-47256","details":"In the Linux kernel, the following vulnerability has been resolved:  mm/memory-failure: make sure wait for page writeback in memory_failure  Our syzkaller trigger the \"BUG_ON(!list_empty(&inode-\u003ei_wb_list))\" in clear_inode:    kernel BUG at fs/inode.c:519!   Internal error: Oops - BUG: 0 [#1] SMP   Modules linked in:   Process syz-executor.0 (pid: 249, stack limit = 0x00000000a12409d7)   CPU: 1 PID: 249 Comm: syz-executor.0 Not tainted 4.19.95   Hardware name: linux,dummy-virt (DT)   pstate: 80000005 (Nzcv daif -PAN -UAO)   pc : clear_inode+0x280/0x2a8   lr : clear_inode+0x280/0x2a8   Call trace:     clear_inode+0x280/0x2a8     ext4_clear_inode+0x38/0xe8     ext4_free_inode+0x130/0xc68     ext4_evict_inode+0xb20/0xcb8     evict+0x1a8/0x3c0     iput+0x344/0x460     do_unlinkat+0x260/0x410     __arm64_sys_unlinkat+0x6c/0xc0     el0_svc_common+0xdc/0x3b0     el0_svc_handler+0xf8/0x160     el0_svc+0x10/0x218   Kernel panic - not syncing: Fatal exception  A crash dump of this problem show that someone called __munlock_pagevec to clear page LRU without lock_page: do_mmap -\u003e mmap_region -\u003e do_munmap -\u003e munlock_vma_pages_range -\u003e __munlock_pagevec.  As a result memory_failure will call identify_page_state without wait_on_page_writeback.  And after truncate_error_page clear the mapping of this page.  end_page_writeback won't call sb_clear_inode_writeback to clear inode-\u003ei_wb_list.  That will trigger BUG_ON in clear_inode!  Fix it by checking PageWriteback too to help determine should we skip wait_on_page_writeback.","modified":"2026-09-01T20:04:37.115409548Z","published":"2024-05-21T15:15:14.380Z","upstream":["CVE-2021-47256"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47256"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47256.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47256.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47256.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}