CVE-2021-47024Public exploit

Local denial of service via RX queue leak

Published Feb 28, 2024 · Updated May 23, 2026

Resource leak in Linux kernel virtio-vsock allows local users to exhaust kernel memory by closing sockets with queued receive packets. Scheduled socket teardown removes the socket from the af_vsock lists without first draining and freeing packets retained on its RX queue. Repeated triggering requires local code execution and an available virtio-vsock transport and can deplete memory until the system becomes unavailable.

CVSS severity5.5
Medium
EPSS probability0.25%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Resource leak in Linux kernel virtio-vsock allows local users to exhaust kernel memory by closing sockets with queued receive packets. Scheduled socket teardown removes the socket from the af_vsock lists without first draining and freeing packets retained on its RX queue. Repeated triggering requires local code execution and an available virtio-vsock transport and can deplete memory until the system becomes unavailable.

The record

CVE
CVE-2021-47024
Published
Feb 28, 2024
Updated
May 23, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-401, T1499.004
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Feb 28, 2024CVE publishedPublication date reported by the CVE source.
  2. May 23, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=4.14.122 <4.15
  2. Affected versionversion=4.19.46 <4.20
  3. Affected versionversion=4.9.179 <4.10
  4. Affected versionversion=4af8a327aeba102aaa9b78f3451f725bc590b237
  5. Affected versionversion=4e539fa2dec4db3405e47002f2878aa4a99eb68b
  6. Affected versionversion=4ea082cd3c400cd5bb36a7beb7e441bf3e29350d
  7. Affected versionversion=5.0.19 <5.1
  8. Affected versionversion=5.1.5 <5.2
  9. Affected versionversion=51adb8ebe8c1d80528fc2ea863cfea9d32d2c52b
  10. Affected versionversion=5.2
  11. Affected versionversion=7d29c9ad0ed525c1b10e29cfca4fb1eece1e93fb
  12. Affected versionversion=ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 <27691665145e74a45034a9dccf1150cf1894763a
  13. Affected versionversion=ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 <37c38674ef2f8d7e8629e5d433c37d6c1273d16b
  14. Affected versionversion=ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 <8432b8114957235f42e070a16118a7f750de9d39
  15. Affected versionversion=ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 <b605673b523fe33abeafb2136759bcbc9c1e6ebf

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=4.14.122 <4.15; version=4.19.46 <4.20; version=4.9.179 <4.10; version=4af8a327aeba102aaa9b78f3451f725bc590b237; version=4e539fa2dec4db3405e47002f2878aa4a99eb68b; version=4ea082cd3c400cd5bb36a7beb7e441bf3e29350d; version=5.0.19 <5.1; version=5.1.5 <5.2; version=51adb8ebe8c1d80528fc2ea863cfea9d32d2c52b; version=5.2; version=7d29c9ad0ed525c1b10e29cfca4fb1eece1e93fb; version=ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 <27691665145e74a45034a9dccf1150cf1894763a; version=ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 <37c38674ef2f8d7e8629e5d433c37d6c1273d16b; version=ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 <8432b8114957235f42e070a16118a7f750de9d39; version=ac03046ece2b158ebd204dfc4896fd9f39f0e6c8 <b605673b523fe33abeafb2136759bcbc9c1e6ebf

Published CVSS scores

5.5NVDCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitPublished

Weakness, pattern, technique

CWE-401Missing Release of Memory after Effective Lifetime
T1499.004Endpoint Denial of Service: Application or System Exploitation

Public exploit references

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo