Vulnary
← back to the feed
Critical· 9.8official fix available

CVE-2021-47107

A buffer overflow in the Linux kernel’s NFS server can let an attacker write beyond a buffer when a client requests a directory listing with a too‑small count. This flaw could crash the server or allow arbitrary code execution. It is rated critical with a CVSS score of 9.8.

publishedMar 4, 2024
last modifiedAug 4, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
55th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 4, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Linux kernel, particularly versions 5.16 and earlier that have not applied the fix. Users running an NFS server on those kernels are at risk.

02

Real-world impact

An attacker could crash the NFS server or potentially run arbitrary code on the server, compromising the confidentiality, integrity, and availability of data served via NFS.

03

Why this severity

The CVSS score is high because the flaw is remotely exploitable without authentication or user interaction and can compromise confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 011. Update your Linux kernel to a version that includes the fix.

NVD description indicates the vulnerability has been resolved.

05

Timeline

  1. Mar 4, 2024 · Mar 4, 2024
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Aug 4, 2026 · 2d ago
    Advisory updated
    The NVD record was last revised.
  3. Aug 5, 2026 · 20h ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2021-47107: A buffer overflow in the Linux kernel’s NFS server can let an attacker · Vulnary