{"id":"DEBIAN-CVE-2021-46921","details":"In the Linux kernel, the following vulnerability has been resolved:  locking/qrwlock: Fix ordering in queued_write_lock_slowpath()  While this code is executed with the wait_lock held, a reader can acquire the lock without holding wait_lock.  The writer side loops checking the value with the atomic_cond_read_acquire(), but only truly acquires the lock when the compare-and-exchange is completed successfully which isn’t ordered. This exposes the window between the acquire and the cmpxchg to an A-B-A problem which allows reads following the lock acquisition to observe values speculatively before the write lock is truly acquired.  We've seen a problem in epoll where the reader does a xchg while holding the read lock, but the writer can see a value change out from under it.    Writer                                | Reader   --------------------------------------------------------------------------------   ep_scan_ready_list()                  |   |- write_lock_irq()                   |       |- queued_write_lock_slowpath()   | \t|- atomic_cond_read_acquire()   | \t\t\t\t        | read_lock_irqsave(&ep-\u003elock, flags);      --\u003e (observes value before unlock) |  chain_epi_lockless()      |                                  |    epi-\u003enext = xchg(&ep-\u003eovflist, epi);      |                                  | read_unlock_irqrestore(&ep-\u003elock, flags);      |                                  |      |     atomic_cmpxchg_relaxed()     |      |-- READ_ONCE(ep-\u003eovflist);        |  A core can order the read of the ovflist ahead of the atomic_cmpxchg_relaxed(). Switching the cmpxchg to use acquire semantics addresses this issue at which point the atomic_cond_read can be switched to use relaxed semantics.  [peterz: use try_cmpxchg()]","modified":"2026-09-15T09:02:34.916055561Z","published":"2024-02-27T10:15:06.990Z","upstream":["CVE-2021-46921"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-46921"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.38-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-46921.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.38-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-46921.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.38-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-46921.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}