CVE-2021-46911
A critical flaw in the Linux kernel’s ch_ktls implementation can cause a kernel panic, potentially crashing the system. The issue stems from improper page reference counting during packet transmission. The vulnerability has been fixed in newer kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, all versions prior to the patch that includes the ch_ktls fix. Linux system administrators and users running affected kernel versions are impacted.
Real-world impact
An attacker could crash the system, leading to a denial‑of‑service condition and disrupting services on the affected machine.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited remotely without authentication or user interaction, and it can lead to complete loss of confidentiality, integrity, and availability.
What to do about it
- 01Upgrade your Linux kernel to a version that includes the ch_ktls patch.
- 02Reboot the system to load the new kernel.
NVD-referenced vendor advisory
Timeline
- Feb 27, 2024 · Feb 27, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 16h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.