CVE-2021-47162
A critical bug in the Linux kernel’s TIPC networking code can cause the system to crash when handling fragmented packets. The flaw arises from improper handling of shared packet fragments, leading to use‑after‑free errors. It has been fixed in a kernel patch that linearizes the packet header before processing.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, including version 5.13 and earlier releases that have not applied the patch.
Real-world impact
An attacker could trigger kernel crashes by sending specially crafted network packets, resulting in a denial‑of‑service that brings the affected system down.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely without authentication, and it compromises confidentiality, integrity, and availability of the system. The lack of required privileges and the high impact on all three security objectives make it a critical risk.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the patch for CVE-2021-47162.
NVD-referenced vendor advisory
Timeline
- Mar 25, 2024 · Mar 25, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 22h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/436d650d374329a591…patch
- git.kernel.org/stable/c/4b1761898861117c97…patch
- git.kernel.org/stable/c/5489f30bb78ff0dafb…patch
- git.kernel.org/stable/c/64d17ec9f1ded042c4…patch
- git.kernel.org/stable/c/6da24cfc83ba4f97ea…patch
- git.kernel.org/stable/c/ace300eecbccaa698e…patch
- git.kernel.org/stable/c/b2c8d28c34b3070407…patch
- git.kernel.org/stable/c/b7df21cf1b79ab7026…patch