LiveActive security incident?Get immediate response
CVE Record

CVE-2021-47418: net_sched: fix NULL deref in fifo_set_limit()

In the Linux kernel, the following vulnerability has been resolved: net_sched: fix NULL deref in fifo_set_limit() syzbot reported another NULL deref in fifo_set_limit() [1] I could repro the issue with : unshare -n tc qd add dev lo root handle 1:0 tbf limit 200000 burst 70000 rate 100Mbit tc qd replace dev lo parent 1:0 pfifo_fast tc qd change dev lo root handle 1:0 tbf limit 300000 burst 70000 rate 100Mbit pfifo_fast does not have a change() operation. Make fifo_set_limit() more robust about this. [1] BUG: kernel NULL pointer dereference, address: 0000000000000000 PGD 1cf99067 P4D 1cf99067 PUD 7ca49067 PMD 0 Oops: 0010 [#1] PREEMPT SMP KASAN CPU: 1 PID: 14443 Comm: syz-executor959 Not tainted 5.15.0-rc3-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011 RIP: 0010:0x0 Code: Unable to access opcode bytes at RIP 0xffffffffffffffd6. RSP: 0018:ffffc9000e2f7310 EFLAGS: 00010246 RAX: dffffc0000000000 RBX: ffffffff8d6ecc00 RCX: 0000000000000000 RDX: 0000000000000000 RSI: ffff888024c27910 RDI: ffff888071e34000 RBP: ffff888071e34000 R08: 0000000000000001 R09: ffffffff8fcfb947 R10: 0000000000000001 R11: 0000000000000000 R12: ffff888024c27910 R13: ffff888071e34018 R14: 0000000000000000 R15: ffff88801ef74800 FS: 00007f321d897700(0000) GS:ffff8880b9d00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: ffffffffffffffd6 CR3: 00000000722c3000 CR4: 00000000003506e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: fifo_set_limit net/sched/sch_fifo.c:242 [inline] fifo_set_limit+0x198/0x210 net/sched/sch_fifo.c:227 tbf_change+0x6ec/0x16d0 net/sched/sch_tbf.c:418 qdisc_change net/sched/sch_api.c:1332 [inline] tc_modify_qdisc+0xd9a/0x1a60 net/sched/sch_api.c:1634 rtnetlink_rcv_msg+0x413/0xb80 net/core/rtnetlink.c:5572 netlink_rcv_skb+0x153/0x420 net/netlink/af_netlink.c:2504 netlink_unicast_kernel net/netlink/af_netlink.c:1314 [inline] netlink_unicast+0x533/0x7d0 net/netlink/af_netlink.c:1340 netlink_sendmsg+0x86d/0xdb0 net/netlink/af_netlink.c:1929 sock_sendmsg_nosec net/socket.c:704 [inline] sock_sendmsg+0xcf/0x120 net/socket.c:724 ____sys_sendmsg+0x6e8/0x810 net/socket.c:2409 ___sys_sendmsg+0xf3/0x170 net/socket.c:2463 __sys_sendmsg+0xe5/0x1b0 net/socket.c:2492 do_syscall_x64 arch/x86/entry/common.c:50 [inline] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80 entry_SYSCALL_64_after_hwframe+0x44/0xae

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-47418 is a Linux kernel crash bug in traffic control scheduling. A crafted sequence of queueing discipline changes can hit a NULL pointer dereference, potentially causing a local denial of service. The sources show kernel fixes but no CVSS score and no evidence of active exploitation.

Executive priority

Handle in the normal kernel patch cycle, with faster action for shared or containerized Linux infrastructure. Current evidence supports denial-of-service risk, not confirmed remote compromise or active exploitation.

Technical view

The flaw is in net_sched fifo_set_limit(), called during qdisc changes such as TBF interacting with pfifo_fast. pfifo_fast lacks a change() operation, and the vulnerable path did not handle that safely, leading to a kernel NULL pointer dereference. Stable kernel commits are referenced as fixes.

Likely exposure

Exposure is most relevant on Linux systems running affected kernel versions where untrusted users or workloads can create network namespaces and manipulate traffic-control queueing disciplines. Container hosts and multi-tenant systems deserve closer review. The bundle lists affected Linux versions through 5.15 but does not map distro package versions.

Exploitation context

The CVE source includes a syzbot crash report and a reproducer context, but KEV is false and the bundle provides no cited evidence of real-world exploitation. Treat this as a local crash-risk issue unless vendor advisories indicate broader impact.

Researcher notes

Evidence is limited to the CVE record, syzbot crash details, affected version metadata, and kernel stable commit references. No CVSS, CWE, distro mapping, or exploitation-in-the-wild evidence is provided in the bundle.

Mitigation direction

  • Update Linux kernels through distro packages that include the referenced stable fixes.
  • Check vendor advisories for exact fixed package versions and backport status.
  • Restrict untrusted access to network namespace and traffic-control capabilities where feasible.
  • Prioritize container hosts, shared Linux servers, and systems allowing untrusted local workloads.

Validation and detection

  • Inventory Linux kernel versions and compare them with vendor fixed packages.
  • Confirm whether stable commits referenced for CVE-2021-47418 are included or backported.
  • Review container and namespace policies for untrusted CAP_NET_ADMIN-equivalent access.
  • Check whether affected hosts run workloads from untrusted users or tenants.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-47418 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
9Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CVECVE Program Container
CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxfb0305ce1b03f6ff17f84f2c63daccecb45f2805, fb0305ce1b03f6ff17f84f2c63daccecb45f2805, fb0305ce1b03f6ff17f84f2c63daccecb45f2805, fb0305ce1b03f6ff17f84f2c63daccecb45f2805, fb0305ce1b03f6ff17f84f2c63daccecb45f2805, fb0305ce1b03f6ff17f84f2c63daccecb45f2805, fb0305ce1b03f6ff17f84f2c63daccecb45f2805, fb0305ce1b03f6ff17f84f2c63daccecb45f2805unaffected
LinuxLinux2.6.27, 0, 4.4.289, 4.9.287, 4.14.251, 4.19.211, 5.4.153, 5.10.73, 5.14.12, 5.15affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.