CVE-2021-46997 is a vulnerability in the Linux kernel, specifically affecting ARM64 architectures. It stems from an inconsistency in how the GIC_PRIO_PSR_I_SET bit in the PMR (Processor Mask Register) is handled during exception entry, leading to a warning when "irqchip.gicv3_pseudo_nmi=1" is enabled and DEBUG_LOCKDEP is selected. This issue can cause the kernel's lockdep mechanism to incorrectly perceive interrupts as unmasked, even though they are hardware-masked. The vulnerability is rated Medium severity with a CVSS score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). This indicates that a local attacker with low privileges could potentially exploit it, leading to a high impact on availability (system crash or denial of service) but no impact on confidentiality or integrity. The attack complexity is low, and no user interaction is required. Currently, there is no evidence of active exploitation, nor are there any known public exploit codes available (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage for this CVE are minimal, which is typical for a significant majority of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10, < 5.10.38CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.11.22CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.12, < 5.12.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.