Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-47477

21
FAUCET Score

CVE-2021-47477 is a high-severity vulnerability in the Linux kernel's Comedi dt9812 driver, affecting systems running Linux. The flaw stems from improper allocation of USB transfer buffers on the stack, leading to potential DMA failures and an information leak. With a CVSS score of 7.8, this vulnerability allows a local attacker with low privileges to achieve high confidentiality, integrity, and availability impacts without user interaction. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.29, < 4.4.292CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.5, < 4.9.290CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.255CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.217CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.159CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.72%
Probability of exploitation in next 30 days
EPSS Percentile
50.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0072 is in the 87th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2021-47477Low

kernel: comedi: dt9812: fix DMA buffers on stack

May 22, 2024

References

git.kernel.org / stable/c/20cebb8b620dc987e55ddc46801de986e081757e
Patch
git.kernel.org / stable/c/365a346cda82f51d835c49136a00a9df8a78c7f2
Patch
git.kernel.org / stable/c/39ea61037ae78f14fa121228dd962ea3280eacf3
Patch
git.kernel.org / stable/c/3ac273d154d634e2034508a14db82a95d7ad12ed
Patch
git.kernel.org / stable/c/3efb7af8ac437085b6c776e5b54830b149d86efe
Patch
git.kernel.org / stable/c/536de747bc48262225889a533db6650731ab25d3
Patch
git.kernel.org / stable/c/786f5b03450454557ff858a8bead5d7c0cbf78d6
Patch
git.kernel.org / stable/c/8a52bc480992c7c9da3ebfea456af731f50a4b97
Patch
git.kernel.org / stable/c/a6af69768d5cb4b2528946d53be5fa19ade37723
Patch