{"id":"DEBIAN-CVE-2021-47221","details":"In the Linux kernel, the following vulnerability has been resolved:  mm/slub: actually fix freelist pointer vs redzoning  It turns out that SLUB redzoning (\"slub_debug=Z\") checks from s-\u003eobject_size rather than from s-\u003einuse (which is normally bumped to make room for the freelist pointer), so a cache created with an object size less than 24 would have the freelist pointer written beyond s-\u003eobject_size, causing the redzone to be corrupted by the freelist pointer.  This was very visible with \"slub_debug=ZF\":    BUG test (Tainted: G    B            ): Right Redzone overwritten   -----------------------------------------------------------------------------    INFO: 0xffff957ead1c05de-0xffff957ead1c05df @offset=1502. First byte 0x1a instead of 0xbb   INFO: Slab 0xffffef3950b47000 objects=170 used=170 fp=0x0000000000000000 flags=0x8000000000000200   INFO: Object 0xffff957ead1c05d8 @offset=1496 fp=0xffff957ead1c0620    Redzone  (____ptrval____): bb bb bb bb bb bb bb bb               ........   Object   (____ptrval____): 00 00 00 00 00 f6 f4 a5               ........   Redzone  (____ptrval____): 40 1d e8 1a aa                        @....   Padding  (____ptrval____): 00 00 00 00 00 00 00 00               ........  Adjust the offset to stay within s-\u003eobject_size.  (Note that no caches of in this size range are known to exist in the kernel currently.)","modified":"2026-09-15T09:02:35.355463092Z","published":"2024-05-21T15:15:11.380Z","upstream":["CVE-2021-47221"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47221"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47221.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47221.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.10.46-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47221.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}