Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-47598

21
FAUCET Score

CVE-2021-47598 is a use-after-free vulnerability in the Linux kernel's sch_cake component, affecting Linux kernel versions. It arises when the cake_init() function improperly calls cake_destroy(), leading to memory being freed prematurely and then potentially accessed again. This vulnerability carries a CVSS score of 7.8 (High), indicating that a local attacker with low privileges could achieve high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.19, < 4.19.222CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.168CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.88CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 52nd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2021-47598Moderate

kernel: sch_cake: do not call cake_destroy() from cake_init()

Jun 19, 2024

References

git.kernel.org / stable/c/0d80462fbdcafd536dcad7569e65d3d14a7e9f2f
Patch
git.kernel.org / stable/c/20ad1ef02f9ad5e1dda9eeb113e4c158b4806986
Patch
git.kernel.org / stable/c/4e388232e630ebe4f94b4a0715ec98c0e2b314a3
Patch
git.kernel.org / stable/c/ab443c53916730862cec202078d36fd4008bea79
Patch
git.kernel.org / stable/c/f6deae2e2d83bd267e1986f5d71d8c458e18fd99
Patch