Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-47409

16
FAUCET Score

CVE-2021-47409 is a null-pointer dereference vulnerability in the Linux kernel's dwc2 USB driver, affecting Linux kernel versions. This medium-severity flaw (CVSS 5.5) can lead to a denial of service (availability impact) if a local attacker with low privileges exploits the unchecked return value of platform_get_resource(). There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.14.250CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.210CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.152CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.72CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.14.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 67th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2021-47409Low

kernel: usb: dwc2: check return value after calling platform_get_resource()

May 21, 2024

References

git.kernel.org / stable/c/2754fa3b73df7d0ae042f3ed6cfd9df9042f6262
Patch
git.kernel.org / stable/c/337f00a0bc62d7cb7d10ec0b872c79009a1641df
Patch
git.kernel.org / stable/c/4b7f4a0eb92bf37bea4cd838c7f83ea42823ca8b
Patch
git.kernel.org / stable/c/856e6e8e0f9300befa87dde09edb578555c99a82
Patch
git.kernel.org / stable/c/8b9c1c33e51d0959f2aec573dfbac0ffd3f5c0b7
Patch
git.kernel.org / stable/c/a7182993dd8e09f96839ddc3ac54f9b37370d282
Patch