Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2021-46938

7.8 · HIGH
Published Feb 27, 2024 linux CWE-415 EPSS 0.25% (16th pctl)

Overview

CVE-2021-46938 is a high-severity vulnerability affecting linux linux_kernel. It was published on February 27, 2024 and has a CVSS 3.1 base score of 7.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

dm rq: fix double free of blk_mq_tag_set in dev remove after table load fails

When loading a device-mapper table for a request-based mapped device,

and the allocation/initialization of the blk_mq_tag_set for the device

fails, a following device remove will cause a double free.

E.g. (dmesg):

device-mapper: core: Cannot initialize queue for request-based dm-mq mapped device

device-mapper: ioctl: unable to set up device queue for new table.

Unable to handle kernel pointer dereference in virtual kernel address space

Failing address: 0305e098835de000 TEID: 0305e098835de803

Fault in home space mode while using kernel ASCE.

AS:000000025efe0007 R3:0000000000000024

Oops: 0038 ilc:3 [#1] SMP

Modules linked in: ... lots of modules ...

Supported: Yes, External

CPU: 0 PID: 7348 Comm: multipathd Kdump: loaded Tainted: G W X 5.3.18-53-default #1 SLE15-SP3

Hardware name: IBM 8561 T01 7I2 (LPAR)

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 4.6.0, < 4.9.269 Affected

Frequently Asked Questions

What is CVE-2021-46938?

CVE-2021-46938 is a high-severity vulnerability affecting linux linux_kernel. It was published on February 27, 2024 and has a CVSS 3.1 base score of 7.8 (HIGH).

How severe is CVE-2021-46938?

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2021-46938?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2021-46938?

CyberStrike's AI-powered security agents can automatically detect CVE-2021-46938 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.