{"id":"DEBIAN-CVE-2021-47492","details":"In the Linux kernel, the following vulnerability has been resolved:  mm, thp: bail out early in collapse_file for writeback page  Currently collapse_file does not explicitly check PG_writeback, instead, page_has_private and try_to_release_page are used to filter writeback pages.  This does not work for xfs with blocksize equal to or larger than pagesize, because in such case xfs has no page-\u003eprivate.  This makes collapse_file bail out early for writeback page.  Otherwise, xfs end_page_writeback will panic as follows.    page:fffffe00201bcc80 refcount:0 mapcount:0 mapping:ffff0003f88c86a8 index:0x0 pfn:0x84ef32   aops:xfs_address_space_operations [xfs] ino:30000b7 dentry name:\"libtest.so\"   flags: 0x57fffe0000008027(locked|referenced|uptodate|active|writeback)   raw: 57fffe0000008027 ffff80001b48bc28 ffff80001b48bc28 ffff0003f88c86a8   raw: 0000000000000000 0000000000000000 00000000ffffffff ffff0000c3e9a000   page dumped because: VM_BUG_ON_PAGE(((unsigned int) page_ref_count(page) + 127u \u003c= 127u))   page-\u003emem_cgroup:ffff0000c3e9a000   ------------[ cut here ]------------   kernel BUG at include/linux/mm.h:1212!   Internal error: Oops - BUG: 0 [#1] SMP   Modules linked in:   BUG: Bad page state in process khugepaged  pfn:84ef32    xfs(E)   page:fffffe00201bcc80 refcount:0 mapcount:0 mapping:0 index:0x0 pfn:0x84ef32    libcrc32c(E) rfkill(E) aes_ce_blk(E) crypto_simd(E) ...   CPU: 25 PID: 0 Comm: swapper/25 Kdump: loaded Tainted: ...   pstate: 60400005 (nZCv daif +PAN -UAO -TCO BTYPE=--)   Call trace:     end_page_writeback+0x1c0/0x214     iomap_finish_page_writeback+0x13c/0x204     iomap_finish_ioend+0xe8/0x19c     iomap_writepage_end_bio+0x38/0x50     bio_endio+0x168/0x1ec     blk_update_request+0x278/0x3f0     blk_mq_end_request+0x34/0x15c     virtblk_request_done+0x38/0x74 [virtio_blk]     blk_done_softirq+0xc4/0x110     __do_softirq+0x128/0x38c     __irq_exit_rcu+0x118/0x150     irq_exit+0x1c/0x30     __handle_domain_irq+0x8c/0xf0     gic_handle_irq+0x84/0x108     el1_irq+0xcc/0x180     arch_cpu_idle+0x18/0x40     default_idle_call+0x4c/0x1a0     cpuidle_idle_call+0x168/0x1e0     do_idle+0xb4/0x104     cpu_startup_entry+0x30/0x9c     secondary_start_kernel+0x104/0x180   Code: d4210000 b0006161 910c8021 94013f4d (d4210000)   ---[ end trace 4a88c6a074082f8c ]---   Kernel panic - not syncing: Oops - BUG: Fatal exception in interrupt","modified":"2026-09-15T09:02:31.965656503Z","published":"2024-05-22T09:15:11.030Z","upstream":["CVE-2021-47492"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47492"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47492.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47492.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47492.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}