CVE-2021-47259
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2021-47259 is a use-after-free vulnerability in the Linux kernel's NFS (Network File System) implementation. The vulnerability was discovered when KASAN (Kernel Address Sanitizer) reported a use-after-free condition that occurs when attempting to mount two different exports through two different NICs that belong to the same server. The issue affects Linux kernels starting from version 4.13 (Kernel Git).

Technical details

The vulnerability exists in the nfs4_init_client() function within the Linux kernel's NFS implementation. The issue stems from incorrect ordering of operations where nfs_put_client() is called before clear_bit(NFS_CS_TSM_POSSIBLE), potentially leading to a use-after-free condition. The bug was traced back to a patch introduced in kernel version 4.13 that changed the refcounting behavior of the clp pointer (Kernel Git). The vulnerability has a CVSS score of 4.4, indicating moderate severity (Rapid7).

Impact

When successfully exploited, this vulnerability could lead to a use-after-free condition in the Linux kernel's NFS implementation, potentially resulting in system crashes or denial of service. The vulnerability specifically affects scenarios where multiple NFS exports are being mounted through different network interfaces on the same server (Kernel Git).

Mitigation and workarounds

The vulnerability has been patched in various Linux distributions and systems. The fix involves reordering the operations in nfs4_init_client() to ensure proper reference counting. Multiple vendors have released security updates, including Huawei EulerOS and Amazon Linux AMI 2. Users are advised to update their systems with the latest security patches (Rapid7).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64564NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel6.12
NoYesAug 04, 2026
CVE-2026-64563NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesAug 04, 2026
CVE-2026-64562NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-5.15
NoYesAug 04, 2026
CVE-2026-64561NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-6.17
NoYesAug 04, 2026
CVE-2022-4994NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-debug-modules
NoYesJul 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management