CVE-2021-47099 affects the Linux kernel's virtual Ethernet (veth) driver, allowing shared or cloned socket buffers to enter Generic Receive Offload (GRO) processing. Under a configuration where GRO is enabled on a veth interface, TCP Segmentation Offload is disabled on its peer, and no XDP program is attached, the condition can trigger a skb_shift kernel BUG during TCP processing and crash the host. The flaw was introduced by commit d3256efd8e8b in Linux 5.13.
Upstream fixed the issue in Linux 5.15.12 and 5.16 by avoiding GRO processing for shared or cloned buffers and attempting to unclone them first. Red Hat issued fixes for supported RHEL 8 and RHEL 9 kernel packages, including RHEL 8.6 EUS via RHSA-2024:1877; RHEL 6 and 7 are outside supported remediation scope. Red Hat rates the issue Low with CVSS 6.0, while CVE.org lists a 7.8 score; organizations should deploy current stable kernel updates and validate affected veth-based container and virtual-networking configurations.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2022:7683 and RHSA-2022:7444 to fix CVE-2021-47099 in RHEL 8 kernel and kernel-rt packages.
Red Hat released RHSA-2024:1877 to address CVE-2021-47099 for RHEL 8.6 Extended Update Support; the advisory also provided a kernel fix for Red Hat Virtualization 4 on RHEL 8.
Red Hat issued RHSA-2022:8267 and RHSA-2022:7933 to address CVE-2021-47099 in RHEL 9 kernel and kernel-rt packages.
Linux kernel 5.15.12 fixed CVE-2021-47099 with commit d2269ae48598, and Linux 5.16 fixed it with commit 9695b7de5b47. The remediation avoids GRO processing for shared or cloned socket buffers and attempts to unclone buffers first.
Commit d3256efd8e8b, included in Linux kernel 5.13, allowed NAPI on veth devices without XDP and introduced a path where shared or cloned socket buffers could enter GRO without a share check.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.