CVE-2021-47496
A flaw in the Linux kernel’s TLS implementation can corrupt memory when error codes are handled incorrectly. The bug was fixed by correcting the sign of error values and adding safeguards. It affects all Linux kernel releases, including 5.15.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, including version 5.15 and other kernel releases.
Real-world impact
An attacker could exploit the memory corruption to execute arbitrary code or crash the system, potentially taking control of the affected machine.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can compromise confidentiality, integrity, and availability without any authentication or user interaction, making it a critical risk.
What to do about it
- 01Update the Linux kernel to a version that includes the CVE-2021-47496 fix.
NVD-referenced vendor advisory
Timeline
- May 22, 2024 · May 22, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.