Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-47321

19
FAUCET Score

CVE-2021-47321 is a use-after-free vulnerability in the Linux kernel's watchdog driver, affecting various Linux kernel versions. It arises because the driver's remove path uses del_timer() instead of del_timer_sync(), allowing the timer handler to execute after the driver is removed, leading to memory corruption. With a CVSS score of 7.8 (HIGH), this vulnerability has a local attack vector, low attack complexity, and can result in high impact to confidentiality, integrity, and availability. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.4.276CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.5, < 4.9.276CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.240CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.198CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.134CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 50th percentile among its peer group of 17,070 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-553.22.1.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: kernel-0:4.18.0-477.75.1.el8_8
View patch

Vendor Advisories (1)

redhatCVE-2021-47321Moderate

kernel: watchdog: Fix possible use-after-free by calling del_timer_sync()

May 21, 2024

References

git.kernel.org / stable/c/1a053c4d716898a53c2e31c574a70ea0c37044a3
Patch
git.kernel.org / stable/c/4c05dac488a660fe2925c047ecb119e7afaaeb1e
Patch
git.kernel.org / stable/c/58606882ad8ec6c39e0f40344b922921ef94ab4d
Patch
git.kernel.org / stable/c/66ba9cf929b1c4fabf545bd4c18f6f64e23e46e4
Patch
git.kernel.org / stable/c/8bec568d7518b1504a602ed5376bb322e4dbb270
Patch
git.kernel.org / stable/c/ca96b8ea5e74956071154bdb456778cc3027e79f
Patch
git.kernel.org / stable/c/d0212f095ab56672f6f36aabc605bda205e1e0bf
Patch
git.kernel.org / stable/c/db222f1477ad5692cd454709b714949807e5d111
Patch
git.kernel.org / stable/c/ecd620e0fb1ff7f78fdb593379b2e6938c99707a
Patch