LiveActive security incident?Get immediate response
CVE Record

CVE-2021-47359: cifs: Fix soft lockup during fsstress

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix soft lockup during fsstress Below traces are observed during fsstress and system got hung. [ 130.698396] watchdog: BUG: soft lockup - CPU#6 stuck for 26s!

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This is a Linux kernel CIFS client reliability vulnerability that can hang a system under filesystem stress. The public record describes a soft lockup observed during fsstress, not data theft or code execution. Business impact is primarily availability for systems using CIFS/SMB network file shares. Public evidence does not show active exploitation.

Executive priority

Treat as an availability issue with uncertain severity. Prioritize patch validation on business-critical Linux systems that depend on SMB file shares, but do not escalate as exploited-in-the-wild based on the supplied sources.

Technical view

CVE-2021-47359 concerns the Linux kernel cifs code path. The stated fix addresses a soft lockup where watchdog reports a CPU stuck during fsstress and the system becomes hung. The source bundle provides Linux kernel version and commit ranges plus stable kernel fix references, but no CVSS score, CWE, or detailed attack preconditions.

Likely exposure

Exposure is most relevant to Linux systems using the CIFS/SMB client, especially file-sharing workloads under stress. The bundle lists Linux kernel versions and commit identifiers, but distribution package mapping is not provided, so validate against the operating system vendor's kernel advisory.

Exploitation context

The CVE record does not indicate KEV listing, active exploitation, public exploit availability, or remote weaponization. The described trigger is filesystem stress leading to a kernel soft lockup and system hang. Evidence is incomplete for determining whether ordinary users or remote servers can reliably trigger it.

Researcher notes

The public bundle is sparse: no CVSS, CWE, exploit status, or detailed root-cause narrative beyond the soft lockup during fsstress. The stable kernel references are the strongest remediation evidence. Further analysis should use kernel commit diffs and distribution advisories, not assumptions about exploitability.

Mitigation direction

  • Check Linux vendor guidance for CVE-2021-47359 and affected kernel packages.
  • Update affected kernels to a vendor build containing the referenced stable fixes.
  • Prioritize systems that mount CIFS/SMB shares for critical workflows.
  • Reduce exposure of nonessential CIFS mounts until patched, where operationally feasible.

Validation and detection

  • Inventory Linux hosts using CIFS/SMB client mounts.
  • Map kernel package versions to vendor advisories for CVE-2021-47359.
  • Review kernel logs for watchdog soft lockup or CIFS-related hangs.
  • Confirm patched hosts include the referenced stable kernel fixes.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-47359 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
3Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux9e992755be8f2d458a0bcbefd19e493483c1dba2, 9e992755be8f2d458a0bcbefd19e493483c1dba2, 0ca6ac8a2691762307beaa4841255d1cfe6b2684unaffected
LinuxLinux5.14, 0, 5.14.9, 5.15affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.