Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2021-47179
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2021-47179 is a vulnerability in the Linux kernel's NFSv4 subsystem that was discovered in March 2024. The vulnerability involves a NULL pointer dereference in the pnfs_mark_matching_lsegs_return() function. This issue occurs when _pnfs_return_layout() passes NULL as the struct pnfs_layout_range argument, which is then dereferenced without proper validation (NVD, Red Hat).

Technical details

The vulnerability is caused by a code change in _pnfs_return_layout() that calls pnfs_mark_matching_lsegs_return() with a NULL argument for the struct pnfs_layout_range parameter. The function fails to check for NULL before dereferencing this pointer, leading to a system crash. The issue has been assigned a CVSS v3.1 base score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local access is required and the primary impact is on system availability (NVD).

Impact

The vulnerability can cause a system crash (kernel oops) when triggered. This has been consistently reproduced during connectathon basic tests on NFS v4.1/v4.2 against Ontap systems. The impact is primarily on system availability, with no direct effect on confidentiality or integrity (Red Hat).

Exploitability

The vulnerability requires local access to the system and can be triggered through NFS v4.1/v4.2 operations. It has been consistently reproducible during testing, particularly when running connectathon basic tests against Ontap systems (Kernel Patch).

Mitigation and workarounds

The vulnerability has been fixed through patches in various Linux kernel versions. The fix involves properly initializing the pnfs_layout_range structure before passing it to the pnfs_mark_matching_lsegs_return() function. Red Hat recommends updating the affected packages as soon as possible, as no practical mitigation exists for this issue (Red Hat).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-aws-7.0
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-aws-7.0
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-hwe-6.17
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-nvidia-6.14
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-7.0
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management