CVE-2021-47352 is an improper input-validation flaw in the Linux kernel's virtio-net driver. A malicious or untrusted virtio device can provide an invalid used-length value, potentially causing data corruption, data loss, or an availability disruption. The upstream fix adds validation of the used length and is included in Linux kernel versions 5.10.51, 5.12.18, 5.13.3, and 5.14 and later stable releases.
Red Hat rated the issue Moderate (CVSS 4.4), while NVD and cve.org assigned scores of 7.8 and 8.4 under different privilege and impact assumptions. Red Hat shipped fixes for affected RHEL 8 kernel and kernel-rt packages through advisories including RHSA-2024:6753, RHSA-2024:6993, RHSA-2024:7000, and RHSA-2024:7001; RHEL 9 is not affected, and RHEL 6 and 7 are outside support scope. No practical mitigation is identified, so organizations should update affected systems to current vendor-supported kernel releases rather than cherry-picking the patch.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:6993 for RHEL 8.8 Extended Update Support and RHSA-2024:7000 and RHSA-2024:7001 for RHEL 8 kernel and kernel-rt packages, addressing CVE-2021-47352.
Red Hat released RHSA-2024:6753, fixing CVE-2021-47352 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
The issue was fixed in Linux kernel versions 5.10.51, 5.12.18, 5.13.3, and 5.14 through commits adding validation for the virtio-net used-length value. The kernel CVE team recommended updating to a current stable release rather than cherry-picking fixes.
The Linux kernel CVE team assigned CVE-2021-47352 to an improper used-length validation flaw in the virtio-net driver. A malicious or invalid length supplied by an untrusted virtio device could cause data corruption or data loss.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.