{"id":"DEBIAN-CVE-2021-47508","details":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: free exchange changeset on failures  Fstests runs on my VMs have show several kmemleak reports like the following.    unreferenced object 0xffff88811ae59080 (size 64):     comm \"xfs_io\", pid 12124, jiffies 4294987392 (age 6.368s)     hex dump (first 32 bytes):       00 c0 1c 00 00 00 00 00 ff cf 1c 00 00 00 00 00  ................       90 97 e5 1a 81 88 ff ff 90 97 e5 1a 81 88 ff ff  ................     backtrace:       [\u003c00000000ac0176d2\u003e] ulist_add_merge+0x60/0x150 [btrfs]       [\u003c0000000076e9f312\u003e] set_state_bits+0x86/0xc0 [btrfs]       [\u003c0000000014fe73d6\u003e] set_extent_bit+0x270/0x690 [btrfs]       [\u003c000000004f675208\u003e] set_record_extent_bits+0x19/0x20 [btrfs]       [\u003c00000000b96137b1\u003e] qgroup_reserve_data+0x274/0x310 [btrfs]       [\u003c0000000057e9dcbb\u003e] btrfs_check_data_free_space+0x5c/0xa0 [btrfs]       [\u003c0000000019c4511d\u003e] btrfs_delalloc_reserve_space+0x1b/0xa0 [btrfs]       [\u003c000000006d37e007\u003e] btrfs_dio_iomap_begin+0x415/0x970 [btrfs]       [\u003c00000000fb8a74b8\u003e] iomap_iter+0x161/0x1e0       [\u003c0000000071dff6ff\u003e] __iomap_dio_rw+0x1df/0x700       [\u003c000000002567ba53\u003e] iomap_dio_rw+0x5/0x20       [\u003c0000000072e555f8\u003e] btrfs_file_write_iter+0x290/0x530 [btrfs]       [\u003c000000005eb3d845\u003e] new_sync_write+0x106/0x180       [\u003c000000003fb505bf\u003e] vfs_write+0x24d/0x2f0       [\u003c000000009bb57d37\u003e] __x64_sys_pwrite64+0x69/0xa0       [\u003c000000003eba3fdf\u003e] do_syscall_64+0x43/0x90  In case brtfs_qgroup_reserve_data() or btrfs_delalloc_reserve_metadata() fail the allocated extent_changeset will not be freed.  So in btrfs_check_data_free_space() and btrfs_delalloc_reserve_space() free the allocated extent_changeset to get rid of the allocated memory.  The issue currently only happens in the direct IO write path, but only after 65b3c08606e5 (\"btrfs: fix ENOSPC failure when attempting direct IO write into NOCOW range\"), and also at defrag_one_locked_target(). Every other place is always calling extent_changeset_free() even if its call to btrfs_delalloc_reserve_space() or btrfs_check_data_free_space() has failed.","modified":"2026-09-01T20:04:37.867822229Z","published":"2024-05-24T15:15:11.573Z","upstream":["CVE-2021-47508"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47508"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.15-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47508.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.15-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47508.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.15-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47508.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}