Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-46997

16
FAUCET Score

CVE-2021-46997 is a vulnerability in the Linux kernel, specifically affecting ARM64 architectures. It stems from an inconsistency in how the GIC_PRIO_PSR_I_SET bit in the PMR (Processor Mask Register) is handled during exception entry, leading to a warning when "irqchip.gicv3_pseudo_nmi=1" is enabled and DEBUG_LOCKDEP is selected. This issue can cause the kernel's lockdep mechanism to incorrectly perceive interrupts as unmasked, even though they are hardware-masked. The vulnerability is rated Medium severity with a CVSS score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). This indicates that a local attacker with low privileges could potentially exploit it, leading to a high impact on availability (system crash or denial of service) but no impact on confidentiality or integrity. The attack complexity is low, and no user interaction is required. Currently, there is no evidence of active exploitation, nor are there any known public exploit codes available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage for this CVE are minimal, which is typical for a significant majority of vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.10, < 5.10.38CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.11.22CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.12, < 5.12.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 68th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2021-46997Low

kernel: arm64: entry: always set GIC_PRIO_PSR_I_SET during entry

Feb 28, 2024

References

git.kernel.org / stable/c/4d6a38da8e79e94cbd1344aa90876f0f805db705
Patch
git.kernel.org / stable/c/51524fa8b5f7b879ba569227738375d283b79382
Patch
git.kernel.org / stable/c/d8d52005f57bbb4a4ec02f647e2555d327135c68
Patch
git.kernel.org / stable/c/e67a83f078005461b59b4c776e6b5addd11725fa
Patch