Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-47435

16
FAUCET Score

CVE-2021-47435 describes a NULL pointer dereference vulnerability in the Linux kernel's device mapper (dm) component. This flaw occurs due to a race condition during I/O completion and DM table swapping, potentially leading to a kernel crash. The vulnerability affects Linux kernel versions and has a CVSS score of 4.7 (Medium). The vulnerability has a local attack vector and high attack complexity, with the primary impact being a denial of service (system crash). There is no confidentiality or integrity impact. The EPSS score is very low, indicating a minimal likelihood of exploitation. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are also absent, suggesting a low level of public awareness or concern.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.313CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.278CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.242CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.193CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.113CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 57th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-372.9.1.rt7.166.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-372.9.1.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: kernel-0:4.18.0-193.87.1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kernel-0:4.18.0-305.57.1.el8_4
View patch

Vendor Advisories (1)

redhatCVE-2021-47435Moderate

kernel: dm: fix mempool NULL pointer race when completing IO

May 22, 2024

References

git.kernel.org / stable/c/6e506f07c5b561d673dd0b0d8f7f420cc48024fb
Patch
git.kernel.org / stable/c/9e07272cca2ed76f7f6073f4444b1143828c8d87
Patch
git.kernel.org / stable/c/9fb7cd5c7fef0f1c982e3cd27745a0dec260eaed
Patch
git.kernel.org / stable/c/ad1393b92e5059218d055bfec8f4946d85ad04c4
Patch
git.kernel.org / stable/c/d208b89401e073de986dc891037c5a668f5d5d95
Patch
git.kernel.org / stable/c/d29c78d3f9c5d2604548c1065bf1ec212728ea61
Patch
git.kernel.org / stable/c/d35aef9c60d310eff3eaddacce301efe877e2b7c
Patch