Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-47634

22
FAUCET Score

CVE-2021-47634 is a use-after-free vulnerability in the Linux kernel's UBI (Unsorted Block Images) subsystem, specifically affecting the ubi_attach and ubi_cdev_ioctl functions. This flaw arises from a race condition between ctrl_cdev_ioctl and ubi_cdev_ioctl due to concurrent lock usage, leading to improper memory management during volume creation and removal. The vulnerability impacts Linux kernel versions and has a CVSS score of 7.8 (High), indicating that a local attacker with low privileges could achieve high confidentiality, integrity, and availability impacts. There is currently no public exploit code available, nor any evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.2.84, < 3.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.10.103, < 3.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.12.63, < 3.13CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.14.77, < 3.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.16.39, < 3.17CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 58th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2021-47634Moderate

kernel: ubi: Fix race condition between ctrl_cdev_ioctl and ubi_cdev_ioctl

Feb 26, 2025

References

git.kernel.org / stable/c/1a3f1cf87054833242fcd0218de0481cf855f888
Patch
git.kernel.org / stable/c/3cbf0e392f173ba0ce425968c8374a6aa3e90f2e
Patch
git.kernel.org / stable/c/432b057f8e847ae5a2306515606f8d2defaca178
Patch
git.kernel.org / stable/c/5f9e9c223e48c264241d2f34d0bfc29e5fcb5c1b
Patch
git.kernel.org / stable/c/a8ecee49259f8f78d91ddb329ab2be7e6fd01974
Patch
git.kernel.org / stable/c/c32fe764191b8ae8b128588beb96e3718d9179d8
Patch
git.kernel.org / stable/c/d727fd32cbd1abf3465f607021bc9c746f17b5a8
Patch
git.kernel.org / stable/c/f149b1bd213820363731aa119e5011ca892a2aac
Patch