{"api_version":"1","generated_at":"2026-08-22T02:57:01+00:00","cve":"CVE-2021-47179","urls":{"html":"https://cve.report/CVE-2021-47179","api":"https://cve.report/api/cve/CVE-2021-47179.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-47179","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-47179"},"summary":{"title":"NFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return()\n\nCommit de144ff4234f changes _pnfs_return_layout() to call\npnfs_mark_matching_lsegs_return() passing NULL as the struct\npnfs_layout_range argument. Unfortunately,\npnfs_mark_matching_lsegs_return() doesn't check if we have a value here\nbefore dereferencing it, causing an oops.\n\nI'm able to hit this crash consistently when running connectathon basic\ntests on NFS v4.1/v4.2 against Ontap.","state":"PUBLISHED","assigner":"Linux","published_at":"2024-03-25 10:15:09","updated_at":"2026-08-04 10:16:50"},"problem_types":["CWE-476"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/f9890652185b72b8de9ebeb4406037640b6e1b53","name":"https://git.kernel.org/stable/c/f9890652185b72b8de9ebeb4406037640b6e1b53","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/39785761feadf261bc5101372b0b0bbaf6a94494","name":"https://git.kernel.org/stable/c/39785761feadf261bc5101372b0b0bbaf6a94494","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/aba3c7795f51717ae316f3566442dee7cc3eeccb","name":"https://git.kernel.org/stable/c/aba3c7795f51717ae316f3566442dee7cc3eeccb","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b090d110e66636bca473fd8b98d5c97b555a965a","name":"https://git.kernel.org/stable/c/b090d110e66636bca473fd8b98d5c97b555a965a","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a421d218603ffa822a0b8045055c03eae394a7eb","name":"https://git.kernel.org/stable/c/a421d218603ffa822a0b8045055c03eae394a7eb","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/42637ca25c7d7b5a92804a679af5192e8c1a9f48","name":"https://git.kernel.org/stable/c/42637ca25c7d7b5a92804a679af5192e8c1a9f48","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4e1ba532dbc1a0e19fc2458d74ab8d98680c4e42","name":"https://git.kernel.org/stable/c/4e1ba532dbc1a0e19fc2458d74ab8d98680c4e42","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-47179","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-47179","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 80e34f4957ec3010c85f9bb0b568a8d46acdf535 4e1ba532dbc1a0e19fc2458d74ab8d98680c4e42 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7b7b9774643220e53eef58c15bb29bd4182fe053 42637ca25c7d7b5a92804a679af5192e8c1a9f48 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9ffa7967f9379a0a1b924e9ffeda709d72237da7 39785761feadf261bc5101372b0b0bbaf6a94494 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6be0e4b59314e4a836495f6ffdc5d2c5b079deeb aba3c7795f51717ae316f3566442dee7cc3eeccb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2fafe7d5047f98791afd9a1d90d2afb70debc590 f9890652185b72b8de9ebeb4406037640b6e1b53 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7e65ea887d0c0997f3053acd91a027af45e71c5b b090d110e66636bca473fd8b98d5c97b555a965a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected de144ff4234f935bd2150108019b5d87a90a8a96 a421d218603ffa822a0b8045055c03eae394a7eb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 96260bde1ea8ae31a5402fe506abbb8951d5a42c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.11.20 5.12 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.9.269 4.9.271 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.14.233 4.14.235 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.19.191 4.19.193 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.4.118 5.4.124 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.10.36 5.10.42 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.12.3 5.12.9 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"47179","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2021-47179","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2024-03-25T15:17:57.286141Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2024-07-05T17:21:16.888Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2024-08-04T05:32:07.318Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/4e1ba532dbc1a0e19fc2458d74ab8d98680c4e42"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/42637ca25c7d7b5a92804a679af5192e8c1a9f48"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/39785761feadf261bc5101372b0b0bbaf6a94494"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/aba3c7795f51717ae316f3566442dee7cc3eeccb"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/f9890652185b72b8de9ebeb4406037640b6e1b53"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/b090d110e66636bca473fd8b98d5c97b555a965a"},{"tags":["x_transferred"],"url":"https://git.kernel.org/stable/c/a421d218603ffa822a0b8045055c03eae394a7eb"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/nfs/pnfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"4e1ba532dbc1a0e19fc2458d74ab8d98680c4e42","status":"affected","version":"80e34f4957ec3010c85f9bb0b568a8d46acdf535","versionType":"git"},{"lessThan":"42637ca25c7d7b5a92804a679af5192e8c1a9f48","status":"affected","version":"7b7b9774643220e53eef58c15bb29bd4182fe053","versionType":"git"},{"lessThan":"39785761feadf261bc5101372b0b0bbaf6a94494","status":"affected","version":"9ffa7967f9379a0a1b924e9ffeda709d72237da7","versionType":"git"},{"lessThan":"aba3c7795f51717ae316f3566442dee7cc3eeccb","status":"affected","version":"6be0e4b59314e4a836495f6ffdc5d2c5b079deeb","versionType":"git"},{"lessThan":"f9890652185b72b8de9ebeb4406037640b6e1b53","status":"affected","version":"2fafe7d5047f98791afd9a1d90d2afb70debc590","versionType":"git"},{"lessThan":"b090d110e66636bca473fd8b98d5c97b555a965a","status":"affected","version":"7e65ea887d0c0997f3053acd91a027af45e71c5b","versionType":"git"},{"lessThan":"a421d218603ffa822a0b8045055c03eae394a7eb","status":"affected","version":"de144ff4234f935bd2150108019b5d87a90a8a96","versionType":"git"},{"status":"affected","version":"96260bde1ea8ae31a5402fe506abbb8951d5a42c","versionType":"git"},{"lessThan":"5.12","status":"affected","version":"5.11.20","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/nfs/pnfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"4.9.271","status":"affected","version":"4.9.269","versionType":"semver"},{"lessThan":"4.14.235","status":"affected","version":"4.14.233","versionType":"semver"},{"lessThan":"4.19.193","status":"affected","version":"4.19.191","versionType":"semver"},{"lessThan":"5.4.124","status":"affected","version":"5.4.118","versionType":"semver"},{"lessThan":"5.10.42","status":"affected","version":"5.10.36","versionType":"semver"},{"lessThan":"5.12.9","status":"affected","version":"5.12.3","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"4.9.271","versionStartIncluding":"4.9.269","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"4.14.235","versionStartIncluding":"4.14.233","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"4.19.193","versionStartIncluding":"4.19.191","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.4.124","versionStartIncluding":"5.4.118","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.42","versionStartIncluding":"5.10.36","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.12.9","versionStartIncluding":"5.12.3","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11.20","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return()\n\nCommit de144ff4234f changes _pnfs_return_layout() to call\npnfs_mark_matching_lsegs_return() passing NULL as the struct\npnfs_layout_range argument. Unfortunately,\npnfs_mark_matching_lsegs_return() doesn't check if we have a value here\nbefore dereferencing it, causing an oops.\n\nI'm able to hit this crash consistently when running connectathon basic\ntests on NFS v4.1/v4.2 against Ontap."}],"metrics":[{"cvssV3_1":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"providerMetadata":{"dateUpdated":"2026-08-04T08:59:16.075Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/4e1ba532dbc1a0e19fc2458d74ab8d98680c4e42"},{"url":"https://git.kernel.org/stable/c/42637ca25c7d7b5a92804a679af5192e8c1a9f48"},{"url":"https://git.kernel.org/stable/c/39785761feadf261bc5101372b0b0bbaf6a94494"},{"url":"https://git.kernel.org/stable/c/aba3c7795f51717ae316f3566442dee7cc3eeccb"},{"url":"https://git.kernel.org/stable/c/f9890652185b72b8de9ebeb4406037640b6e1b53"},{"url":"https://git.kernel.org/stable/c/b090d110e66636bca473fd8b98d5c97b555a965a"},{"url":"https://git.kernel.org/stable/c/a421d218603ffa822a0b8045055c03eae394a7eb"}],"title":"NFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2021-47179","datePublished":"2024-03-25T09:16:28.787Z","dateReserved":"2024-03-25T09:12:14.112Z","dateUpdated":"2026-08-04T08:59:16.075Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2024-03-25 10:15:09","lastModifiedDate":"2026-08-04 10:16:50","problem_types":["CWE-476"],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-03-25T15:17:57.286141Z","id":"CVE-2021-47179","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9.269","versionEndExcluding":"4.9.271","matchCriteriaId":"498E5552-CBDA-4FE4-8844-EE7D575C9F35"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14.233","versionEndExcluding":"4.14.235","matchCriteriaId":"F80A9838-744C-4554-8CCE-B87128CC7170"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.191","versionEndExcluding":"4.19.193","matchCriteriaId":"BE4BABC9-D544-4D14-BF94-5E999CDF4847"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.118","versionEndExcluding":"5.4.124","matchCriteriaId":"255B5502-D9A3-44BD-9B79-7C957CA4B62B"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.36","versionEndExcluding":"5.10.42","matchCriteriaId":"FAF8C28F-086A-4EC2-A931-2237C11F5F54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12.3","versionEndExcluding":"5.12.9","matchCriteriaId":"148AD795-DE39-4B4E-BDFF-D6A492C22C4C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"47179","Ordinal":"1","Title":"NFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lseg","CVE":"CVE-2021-47179","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"47179","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return()\n\nCommit de144ff4234f changes _pnfs_return_layout() to call\npnfs_mark_matching_lsegs_return() passing NULL as the struct\npnfs_layout_range argument. Unfortunately,\npnfs_mark_matching_lsegs_return() doesn't check if we have a value here\nbefore dereferencing it, causing an oops.\n\nI'm able to hit this crash consistently when running connectathon basic\ntests on NFS v4.1/v4.2 against Ontap.","Type":"Description","Title":"NFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lseg"}]}}}