cbcvebase.
CVE-2021-47507
published 2024-05-24

CVE-2021-47507: In the Linux kernel, the following vulnerability has been resolved: nfsd: Fix nsfd startup race (again) Commit bd5ae9288d64 ("nfsd: register pernet ops last…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: nfsd: Fix nsfd startup race (again) Commit bd5ae9288d64 ("nfsd: register pernet ops last, unregister first") has re-opened rpc_pipefs_event() race against nfsd_net_id registration (register_pernet_subsys()) which has been fixed by commit bb7ffbf29e76 ("nfsd: fix nsfd startup race triggering BUG_ON"). Restore the order of register_pernet_subsys() vs register_cld_notifier(). Add WARN_ON() to prevent a future regression. Crash info: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000012 CPU: 8 PID: 345 Comm: mount Not tainted 5.4.144-... #1 pc : rpc_pipefs_event+0x54/0x120 [nfsd] lr : rpc_pipefs_event+0x48/0x120 [nfsd] Call trace: rpc_pipefs_event+0x54/0x120 [nfsd] blocking_notifier_call_chain rpc_fill_super get_tree_keyed rpc_fs_get_tree vfs_get_tree do_mount ksys_mount __arm64_sys_mount el0_svc_handler el0_svc

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.15.15-1 (bookworm)linux 5.15.15-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.10.20 < 5.10.855.10.85
linuxlinux>= 5.11.3 < 5.125.12
linuxlinux>= 5.4.102 < 5.4.1655.4.165
linuxlinux>= 7c7cb07d4affcf41749234fe9dc4d90cd3959e32 < c520943a00ad5015704969ad3304c956bcd49d25c520943a00ad5015704969ad3304c956bcd49d25
linuxlinux>= 8677e99150b0830d29cc1318b4cc559e176940bb < f5734b1714ca355703e9ea8fb61d04beff1790b9f5734b1714ca355703e9ea8fb61d04beff1790b9
linuxlinux>= bd5ae9288d6451bd346a1b4a59d4fe7e62ba29b7 < 8bf902fee5893cfc2f04a698abab47629699ae9a8bf902fee5893cfc2f04a698abab47629699ae9a
linuxlinux>= bd5ae9288d6451bd346a1b4a59d4fe7e62ba29b7 < b10252c7ae9c9d7c90552f88b544a44ee773af64b10252c7ae9c9d7c90552f88b544a44ee773af64
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.92-15.10.92-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 0 < 5.15.15-15.15.15-1
linuxlinux_kernel>= 5.10.20 < 5.10.855.10.85
linuxlinux_kernel>= 5.11.3 < 5.15.85.15.8
linuxlinux_kernel>= 5.4.102 < 5.4.1655.4.165

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.