CVE-2021-47461 is a race condition in the Linux kernel's userfaultfd subsystem, triggered when userfaultfd_writeprotect() runs concurrently with exit_mmap() as a process exits and its virtual-memory areas are removed. Introduced in kernel 5.7, the flaw was detected with KASAN and can affect confidentiality, integrity, and availability; Red Hat rated it CVSS 7.0, while NVD assigned 4.7 primarily for availability impact.
The upstream issue is fixed in Linux stable releases 5.10.76, 5.14.15, and 5.15 and later. Red Hat released corrected RHEL 8 kernel and kernel-rt packages through errata issued between August and November 2024; RHEL 9 is not affected, while RHEL 6 and 7 are outside supported remediation scope. Organizations should deploy a current vendor-supported kernel release rather than cherry-picking the individual patch.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:5101 for RHEL 8 kernel packages and RHSA-2024:5102 for RHEL 8 kernel-rt packages, addressing CVE-2021-47461.
Red Hat issued RHSA-2024:10262 to address CVE-2021-47461 in RHEL 8.8 Extended Update Support kernel packages.
RHSA-2024:6297 addressed CVE-2021-47461 kernel packages for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
The Linux kernel CVE team assigned CVE-2021-47461 to the userfaultfd race condition, which can occur when a process exits while virtual memory areas are removed concurrently with a write-protect request.
A race between userfaultfd_writeprotect() and exit_mmap() in fs/userfaultfd.c was introduced in Linux kernel 5.7. Upstream fixes using mmget_not_zero() were included in stable kernel versions 5.10.76, 5.14.15, and 5.15.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.