CVE-2021-47107
A buffer overflow in the Linux kernel’s NFS server can let an attacker write beyond a buffer when a client requests a directory listing with a too‑small count. This flaw could crash the server or allow arbitrary code execution. It is rated critical with a CVSS score of 9.8.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, particularly versions 5.16 and earlier that have not applied the fix. Users running an NFS server on those kernels are at risk.
Real-world impact
An attacker could crash the NFS server or potentially run arbitrary code on the server, compromising the confidentiality, integrity, and availability of data served via NFS.
Why this severity
The CVSS score is high because the flaw is remotely exploitable without authentication or user interaction and can compromise confidentiality, integrity, and availability.
What to do about it
- 011. Update your Linux kernel to a version that includes the fix.
NVD description indicates the vulnerability has been resolved.
Timeline
- Mar 4, 2024 · Mar 4, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 20h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/53b1119a6e5028b125…exploitmailing listpatch
- git.kernel.org/stable/c/9e291a6a28d32545ed…exploitmailing listpatch
- git.kernel.org/stable/c/eabc0aab98e5218cee…exploitmailing listpatch
- cert-portal.siemens.com/productcert/html/ssa-265688…