{"id":"DEBIAN-CVE-2021-47638","details":"In the Linux kernel, the following vulnerability has been resolved:  ubifs: rename_whiteout: Fix double free for whiteout_ui-\u003edata  'whiteout_ui-\u003edata' will be freed twice if space budget fail for rename whiteout operation as following process:  rename_whiteout   dev = kmalloc   whiteout_ui-\u003edata = dev   kfree(whiteout_ui-\u003edata)  // Free first time   iput(whiteout)     ubifs_free_inode       kfree(ui-\u003edata)\t    // Double free!  KASAN reports: ================================================================== BUG: KASAN: double-free or invalid-free in ubifs_free_inode+0x4f/0x70 Call Trace:   kfree+0x117/0x490   ubifs_free_inode+0x4f/0x70 [ubifs]   i_callback+0x30/0x60   rcu_do_batch+0x366/0xac0   __do_softirq+0x133/0x57f  Allocated by task 1506:   kmem_cache_alloc_trace+0x3c2/0x7a0   do_rename+0x9b7/0x1150 [ubifs]   ubifs_rename+0x106/0x1f0 [ubifs]   do_syscall_64+0x35/0x80  Freed by task 1506:   kfree+0x117/0x490   do_rename.cold+0x53/0x8a [ubifs]   ubifs_rename+0x106/0x1f0 [ubifs]   do_syscall_64+0x35/0x80  The buggy address belongs to the object at ffff88810238bed8 which belongs to the cache kmalloc-8 of size 8 ==================================================================  Let ubifs_free_inode() free 'whiteout_ui-\u003edata'. BTW, delete unused assignment 'whiteout_ui-\u003edata_len = 0', process 'ubifs_evict_inode() -\u003e ubifs_jnl_delete_inode() -\u003e ubifs_jnl_write_inode()' doesn't need it (because 'inc_nlink(whiteout)' won't be excuted by 'goto out_release',  and the nlink of whiteout inode is 0).","modified":"2026-09-15T09:02:32.134979039Z","published":"2025-02-26T06:37:05.580Z","upstream":["CVE-2021-47638"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47638"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47638.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47638.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.17.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47638.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}