CVE-2021-46990

Process crashes via concurrent entry-flush patching

Published Feb 28, 2024 · Updated May 23, 2026

Race condition in the Linux kernel powerpc/64s entry-flush mitigation allows local users to crash processes through the entry_flush debugfs control. Runtime mitigation toggling patches a fallback entry-flush call while other CPUs can execute it, allowing partially patched code to skip link-register restoration. Reachability requires a powerpc/64s system, concurrent CPUs, and permission to write the debugfs control; the demonstrated consequence is a user-process crash.

CVSS severity5.5
Medium
EPSS probability0.23%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Race condition in the Linux kernel powerpc/64s entry-flush mitigation allows local users to crash processes through the entry_flush debugfs control. Runtime mitigation toggling patches a fallback entry-flush call while other CPUs can execute it, allowing partially patched code to skip link-register restoration. Reachability requires a powerpc/64s system, concurrent CPUs, and permission to write the debugfs control; the demonstrated consequence is a user-process crash.

The record

CVE
CVE-2021-46990
Published
Feb 28, 2024
Updated
May 23, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
T1499
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Feb 28, 2024CVE publishedPublication date reported by the CVE source.
  2. May 23, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=4.14.208 <4.14.233
  2. Affected versionversion=4.19.159 <4.19.191
  3. Affected versionversion=4.4.245 <4.4.269
  4. Affected versionversion=4.9.245 <4.9.269
  5. Affected versionversion=4a1e90af718d1489ffcecc8f52486c4f5dc0f7a6 <8382b15864e5014261b4f36c2aa89723612ee058
  6. Affected versionversion=5.10
  7. Affected versionversion=5.4.79 <5.4.120
  8. Affected versionversion=5.9.10 <5.10
  9. Affected versionversion=b65458b6be8032c5179d4f562038575d7b3a6be3 <0b4eb172cc12dc102cd0ad013e53ee4463db9508
  10. Affected versionversion=db01cad9efe3c3838a6b3a3f68affd295c4b92d6 <ee4b7aab93c2631c3bb0753023c5dda592bb666b
  11. Affected versionversion=e590b36718d6e740b7b19514f710402a6499164c
  12. Affected versionversion=f69bb4e51f41973fb7594be1479fa689831efe1a <2db22ba4e0e103f00e0512e0ecce36ac78c644f8
  13. Affected versionversion=f79643787e0a0762d2409b7b8334e83f22d85695 <5bc00fdda1e934c557351a9c751a205293e68cbf
  14. Affected versionversion=f79643787e0a0762d2409b7b8334e83f22d85695 <aec86b052df6541cc97c5fca44e5934cbea4963b
  15. Affected versionversion=f79643787e0a0762d2409b7b8334e83f22d85695 <d2e3590ca39ccfd8a5a46d8c7f095cb6c7b9ae92
  16. Affected versionversion=f79643787e0a0762d2409b7b8334e83f22d85695 <dd0d6117052faace5440db20fc37175efe921c7d
  17. Affected versionversion=fa4bf9f38184ed7ca4916eb64f8c767d1e279c1f <0c25a7bb697f2e6ee65b6d63782f675bf129511a

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=4.14.208 <4.14.233; version=4.19.159 <4.19.191; version=4.4.245 <4.4.269; version=4.9.245 <4.9.269; version=4a1e90af718d1489ffcecc8f52486c4f5dc0f7a6 <8382b15864e5014261b4f36c2aa89723612ee058; version=5.10; version=5.4.79 <5.4.120; version=5.9.10 <5.10; version=b65458b6be8032c5179d4f562038575d7b3a6be3 <0b4eb172cc12dc102cd0ad013e53ee4463db9508; version=db01cad9efe3c3838a6b3a3f68affd295c4b92d6 <ee4b7aab93c2631c3bb0753023c5dda592bb666b; version=e590b36718d6e740b7b19514f710402a6499164c; version=f69bb4e51f41973fb7594be1479fa689831efe1a <2db22ba4e0e103f00e0512e0ecce36ac78c644f8; version=f79643787e0a0762d2409b7b8334e83f22d85695 <5bc00fdda1e934c557351a9c751a205293e68cbf; version=f79643787e0a0762d2409b7b8334e83f22d85695 <aec86b052df6541cc97c5fca44e5934cbea4963b; version=f79643787e0a0762d2409b7b8334e83f22d85695 <d2e3590ca39ccfd8a5a46d8c7f095cb6c7b9ae92; version=f79643787e0a0762d2409b7b8334e83f22d85695 <dd0d6117052faace5440db20fc37175efe921c7d; version=fa4bf9f38184ed7ca4916eb64f8c767d1e279c1f <0c25a7bb697f2e6ee65b6d63782f675bf129511a

Published CVSS scores

5.5NIST NVDCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

T1499Endpoint Denial of Service

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo