
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-47179 is a vulnerability in the Linux kernel's NFSv4 subsystem that was discovered in March 2024. The vulnerability involves a NULL pointer dereference in the pnfs_mark_matching_lsegs_return() function. This issue occurs when _pnfs_return_layout() passes NULL as the struct pnfs_layout_range argument, which is then dereferenced without proper validation (NVD, Red Hat).
The vulnerability is caused by a code change in _pnfs_return_layout() that calls pnfs_mark_matching_lsegs_return() with a NULL argument for the struct pnfs_layout_range parameter. The function fails to check for NULL before dereferencing this pointer, leading to a system crash. The issue has been assigned a CVSS v3.1 base score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local access is required and the primary impact is on system availability (NVD).
The vulnerability can cause a system crash (kernel oops) when triggered. This has been consistently reproduced during connectathon basic tests on NFS v4.1/v4.2 against Ontap systems. The impact is primarily on system availability, with no direct effect on confidentiality or integrity (Red Hat).
The vulnerability requires local access to the system and can be triggered through NFS v4.1/v4.2 operations. It has been consistently reproducible during testing, particularly when running connectathon basic tests against Ontap systems (Kernel Patch).
The vulnerability has been fixed through patches in various Linux kernel versions. The fix involves properly initializing the pnfs_layout_range structure before passing it to the pnfs_mark_matching_lsegs_return() function. Red Hat recommends updating the affected packages as soon as possible, as no practical mitigation exists for this issue (Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."