CVE-2021-47260
published 2024-05-21CVE-2021-47260: In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a potential NULL dereference in nfs_get_client() None of the callers are expecting…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.24%
14.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
NFS: Fix a potential NULL dereference in nfs_get_client()
None of the callers are expecting NULL returns from nfs_get_client() so
this code will lead to an Oops. It's better to return an error
pointer. I expect that this is dead code so hopefully no one is
affected.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.46-1 (bookworm) | linux 5.10.46-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 31434f496abb9f3410b10f541462fe58613dd3ad < fab8bfdfb4aac9e4e8363666333adfdf21e89106 | fab8bfdfb4aac9e4e8363666333adfdf21e89106 |
| linux | linux | >= 31434f496abb9f3410b10f541462fe58613dd3ad < a979e601000982a3ca693171a6d4dffc47f8ad00 | a979e601000982a3ca693171a6d4dffc47f8ad00 |
| linux | linux | >= 31434f496abb9f3410b10f541462fe58613dd3ad < 634f17ff1d59905eb3b4bbbc00805961d08beaee | 634f17ff1d59905eb3b4bbbc00805961d08beaee |
| linux | linux | >= 31434f496abb9f3410b10f541462fe58613dd3ad < 4b380a7d84ef2ce3f4f5bec5d8706ed937ac6502 | 4b380a7d84ef2ce3f4f5bec5d8706ed937ac6502 |
| linux | linux | >= 31434f496abb9f3410b10f541462fe58613dd3ad < 0057ecef9f324007c0ba5fcca4ddd131178ce78b | 0057ecef9f324007c0ba5fcca4ddd131178ce78b |
| linux | linux | >= 31434f496abb9f3410b10f541462fe58613dd3ad < 279ad78a00f8b9c5ff24171a59297187a3bd44b7 | 279ad78a00f8b9c5ff24171a59297187a3bd44b7 |
| linux | linux | >= 31434f496abb9f3410b10f541462fe58613dd3ad < 58ddf61f10b8f9b7b1341644bfee2f1c6508d4e1 | 58ddf61f10b8f9b7b1341644bfee2f1c6508d4e1 |
| linux | linux | >= 31434f496abb9f3410b10f541462fe58613dd3ad < 09226e8303beeec10f2ff844d2e46d1371dc58e0 | 09226e8303beeec10f2ff844d2e46d1371dc58e0 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 4.4.0-270.304 | 4.4.0-270.304 |
| linux | linux_kernel | >= 3.17 < 4.4.273 | 4.4.273 |
| linux | linux_kernel | >= 4.10 < 4.14.237 | 4.14.237 |
| linux | linux_kernel | >= 4.15 < 4.19.195 | 4.19.195 |
| linux | linux_kernel | >= 4.20 < 5.4.126 | 5.4.126 |
| linux | linux_kernel | >= 4.5 < 4.9.273 | 4.9.273 |
| linux | linux_kernel | >= 5.11 < 5.12.11 | 5.12.11 |
| linux | linux_kernel | >= 5.5 < 5.10.44 | 5.10.44 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
linux-kvm vulnerabilities
osv·2025-07-08·CVSS 5.5
CVE-2022-3640 [MEDIUM] linux-kvm vulnerabilities
linux-kvm vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
Bluetooth stack in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2022-3640)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SCSI subsystem;
- Network file system (NFS) client;
- NILFS2 file system;
- File systems infrastructure;
- Memory management;
- Bluetooth subsystem;
- Network traffic control;
- USB sound devices;
(CVE-2024-50116, CVE-2021-47576, CVE-2024-53197, CVE-2024-46787,
CVE-2025-37798, CVE-2024-49958, CVE-2021-47260, CVE-2025-37932,
CVE-2022-49909)
OSV
linux, linux-aws, linux-lts-xenial vulnerabilities
osv·2025-07-01·CVSS 5.5
CVE-2022-3640 [MEDIUM] linux, linux-aws, linux-lts-xenial vulnerabilities
linux, linux-aws, linux-lts-xenial vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
Bluetooth stack in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2022-3640)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SCSI subsystem;
- Network file system (NFS) client;
- NILFS2 file system;
- File systems infrastructure;
- Memory management;
- Bluetooth subsystem;
- Network traffic control;
- USB sound devices;
(CVE-2024-50116, CVE-2021-47576, CVE-2024-53197, CVE-2024-46787,
CVE-2025-37798, CVE-2024-49958, CVE-2021-47260, CVE-2025-37932,
CVE-2
OSV
linux-fips vulnerabilities
osv·2025-07-01·CVSS 5.5
CVE-2022-3640 [MEDIUM] linux-fips vulnerabilities
linux-fips vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
Bluetooth stack in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2022-3640)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SCSI subsystem;
- Network file system (NFS) client;
- NILFS2 file system;
- File systems infrastructure;
- Memory management;
- Bluetooth subsystem;
- Network traffic control;
- USB sound devices;
(CVE-2024-50116, CVE-2021-47576, CVE-2024-53197, CVE-2024-46787,
CVE-2025-37798, CVE-2024-49958, CVE-2021-47260, CVE-2025-37932,
CVE-2022-49909)
GHSA
GHSA-2qgr-37h8-x3w9: In the Linux kernel, the following vulnerability has been resolved:
NFS: Fix a potential NULL dereference in nfs_get_client()
None of the callers ar
ghsa_unreviewed·2024-05-21
CVE-2021-47260 [MEDIUM] CWE-476 GHSA-2qgr-37h8-x3w9: In the Linux kernel, the following vulnerability has been resolved:
NFS: Fix a potential NULL dereference in nfs_get_client()
None of the callers ar
In the Linux kernel, the following vulnerability has been resolved:
NFS: Fix a potential NULL dereference in nfs_get_client()
None of the callers are expecting NULL returns from nfs_get_client() so
this code will lead to an Oops. It's better to return an error
pointer. I expect that this is dead code so hopefully no one is
affected.
OSV
CVE-2021-47260: In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a potential NULL dereference in nfs_get_client() None of the callers are
osv·2024-05-21·CVSS 5.5
CVE-2021-47260 [MEDIUM] CVE-2021-47260: In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a potential NULL dereference in nfs_get_client() None of the callers are
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a potential NULL dereference in nfs_get_client() None of the callers are expecting NULL returns from nfs_get_client() so this code will lead to an Oops. It's better to return an error pointer. I expect that this is dead code so hopefully no one is affected.
Ubuntu
Linux kernel (KVM) vulnerabilities
vendor_ubuntu·2025-07-08·CVSS 5.5
CVE-2021-47260 [MEDIUM] Linux kernel (KVM) vulnerabilities
Title: Linux kernel (KVM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a use-after-free vulnerability existed in the
Bluetooth stack in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2022-3640)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SCSI subsystem;
- Network file system (NFS) client;
- NILFS2 file system;
- File systems infrastructure;
- Memory management;
- Bluetooth subsystem;
- Network traffic control;
- USB sound devices;
(CVE-2024-50116, CVE-2021-47576, CVE-2024-53197, CVE-2024-46787,
CVE-2025-377
Ubuntu
Linux kernel (FIPS) vulnerabilities
vendor_ubuntu·2025-07-01·CVSS 5.5
CVE-2022-3640 [MEDIUM] Linux kernel (FIPS) vulnerabilities
Title: Linux kernel (FIPS) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a use-after-free vulnerability existed in the
Bluetooth stack in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2022-3640)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SCSI subsystem;
- Network file system (NFS) client;
- NILFS2 file system;
- File systems infrastructure;
- Memory management;
- Bluetooth subsystem;
- Network traffic control;
- USB sound devices;
(CVE-2024-50116, CVE-2021-47576, CVE-2024-53197, CVE-2024-46787,
CVE-2025-37
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2025-07-01·CVSS 5.5
CVE-2022-3640 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that a use-after-free vulnerability existed in the
Bluetooth stack in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2022-3640)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SCSI subsystem;
- Network file system (NFS) client;
- NILFS2 file system;
- File systems infrastructure;
- Memory management;
- Bluetooth subsystem;
- Network traffic control;
- USB sound devices;
(CVE-2024-50116, CVE-2021-47576, CVE-2024-53197, CVE-2024-46787,
CVE-2025-37798, CV
Red Hat
kernel: NFS: Fix a potential NULL dereference in nfs_get_client()
vendor_redhat·2024-05-21·CVSS 5.5
CVE-2021-47260 [MEDIUM] CWE-476 kernel: NFS: Fix a potential NULL dereference in nfs_get_client()
kernel: NFS: Fix a potential NULL dereference in nfs_get_client()
In the Linux kernel, the following vulnerability has been resolved:
NFS: Fix a potential NULL dereference in nfs_get_client()
None of the callers are expecting NULL returns from nfs_get_client() so
this code will lead to an Oops. It's better to return an error
pointer. I expect that this is dead code so hopefully no one is
affected.
A vulnerability was found in the Linux kernel's NFS client code in the nfs_get_client() function. If this function unexpectedly returns a NULL value, it can cause the kernel to crash.
Statement: This vulnerability is rated as a moderate severity because it involves a NULL dereference that could crash the kernel, exploitation requires specific conditions.
Mitigation: Red Hat has investigated w
Debian
CVE-2021-47260: linux - In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a ...
vendor_debian·2021·CVSS 5.5
CVE-2021-47260 [MEDIUM] CVE-2021-47260: linux - In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a ...
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a potential NULL dereference in nfs_get_client() None of the callers are expecting NULL returns from nfs_get_client() so this code will lead to an Oops. It's better to return an error pointer. I expect that this is dead code so hopefully no one is affected.
Scope: local
bookworm: resolved (fixed in 5.10.46-1)
bullseye: resolved (fixed in 5.10.46-1)
forky: resolved (fixed in 5.10.46-1)
sid: resolved (fixed in 5.10.46-1)
trixie: resolved (fixed in 5.10.46-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0057ecef9f324007c0ba5fcca4ddd131178ce78bhttps://git.kernel.org/stable/c/09226e8303beeec10f2ff844d2e46d1371dc58e0https://git.kernel.org/stable/c/279ad78a00f8b9c5ff24171a59297187a3bd44b7https://git.kernel.org/stable/c/4b380a7d84ef2ce3f4f5bec5d8706ed937ac6502https://git.kernel.org/stable/c/58ddf61f10b8f9b7b1341644bfee2f1c6508d4e1https://git.kernel.org/stable/c/634f17ff1d59905eb3b4bbbc00805961d08beaeehttps://git.kernel.org/stable/c/a979e601000982a3ca693171a6d4dffc47f8ad00https://git.kernel.org/stable/c/fab8bfdfb4aac9e4e8363666333adfdf21e89106https://git.kernel.org/stable/c/0057ecef9f324007c0ba5fcca4ddd131178ce78bhttps://git.kernel.org/stable/c/09226e8303beeec10f2ff844d2e46d1371dc58e0https://git.kernel.org/stable/c/279ad78a00f8b9c5ff24171a59297187a3bd44b7https://git.kernel.org/stable/c/4b380a7d84ef2ce3f4f5bec5d8706ed937ac6502https://git.kernel.org/stable/c/58ddf61f10b8f9b7b1341644bfee2f1c6508d4e1https://git.kernel.org/stable/c/634f17ff1d59905eb3b4bbbc00805961d08beaeehttps://git.kernel.org/stable/c/a979e601000982a3ca693171a6d4dffc47f8ad00https://git.kernel.org/stable/c/fab8bfdfb4aac9e4e8363666333adfdf21e89106
2024-05-21
Published