Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-47456

21
FAUCET Score

CVE-2021-47456 is a Use-After-Free (UAF) vulnerability in the Linux kernel's peak_pci module, affecting Linux kernel versions. This flaw occurs during module removal when 'chan' is referenced after 'dev' has been prematurely released, leading to memory corruption. With a CVSS score of 8.4 (High), it presents a significant risk, allowing for potential local privilege escalation and impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.4, < 4.4.290CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.5, < 4.9.288CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.253CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.214CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.156CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.4HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.5
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
14.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 17th percentile among its peer group of 3,241 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.8.1.rt7.349.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.8.1.el8_10
View patch

Vendor Advisories (1)

redhatCVE-2021-47456Low

kernel: can: peak_pci: peak_pci_remove(): fix UAF

May 22, 2024

References

git.kernel.org / stable/c/0e5afdc2315b0737edcf55bede4ee1640d2d464d
Patch
git.kernel.org / stable/c/1248582e47a9f7ce0ecd156c39fc61f8b6aa3699
Patch
git.kernel.org / stable/c/1c616528ba4aeb1125a06b407572ab7b56acae38
Patch
git.kernel.org / stable/c/28f28e4bc3a5e0051faa963f10b778ab38c1db69
Patch
git.kernel.org / stable/c/34914971bb3244db4ce2be44e9438a9b30c56250
Patch
git.kernel.org / stable/c/447d44cd2f67a20b596ede3ca3cd67086dfd9ca9
Patch
git.kernel.org / stable/c/949fe9b35570361bc6ee2652f89a0561b26eec98
Patch
git.kernel.org / stable/c/adbda14730aacce41c0d3596415aa39ad63eafd9
Patch