CVE-2021-47199
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2021-47199 affects the Linux kernel's network subsystem, specifically in the net/mlx5e CT (Connection Tracking) component. The vulnerability was discovered in versions from 5.7 through 5.15.5 and 5.16-rc1. The issue involves multiple allocations and memory leaks in mod acts when handling CT clear action offload operations (NVD).

Technical details

The vulnerability occurs when CT clear action offload adds additional mod hdr actions to the flow's original mod actions to clear registers holding ct_state. When a flow includes encap action, a neigh update event can trigger the driver to unoffload and then reoffload the flow. This process causes the ct clear handling to repeatedly add the same set of mod hdr actions until reaching the maximum limit. Additionally, the driver fails to release the allocated mod hdr actions, resulting in a memory leak (Kernel Patch).

Impact

The vulnerability can lead to memory leaks in the Linux kernel's networking stack, potentially affecting system stability and resource availability over time. The issue has been assigned a CVSS v3.1 Base Score of 5.5 (Medium) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Exploitability

The vulnerability requires local access and low privileges to exploit. It primarily affects systems using the MLX5 network driver with connection tracking features enabled (NVD).

Mitigation and workarounds

The issue has been fixed by moving CT clear mod acts allocation into the parsing actions phase and only using it when offloading the rule. The release of mod acts is now handled in the normal flow_put(). Users should update to Linux kernel versions that include the fix (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-fips
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-nvidia-tegra-5.15
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-fips
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-4.15
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management