CVE-2021-47055 - CVE House
Back to Database
Status published Medium CVE-2021-47055

mtd: require write permissions for locking and badblock ioctls

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: mtd: require write permissions for locking and badblock ioctls MEMLOCK, MEMUNLOCK and OTPLOCK modify protection bits. Thus require write permission. Depending on the hardware MEMLOCK might even be write-once, e.g. for SPI-NOR flashes with their WP# tied to GND. OTPLOCK is always write-once. MEMSETBADBLOCK modifies the bad block table.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47055

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
1c9f9125892a43901438bf704ada6b7019e2a884, 583d42400532fbd6228b0254d7c732b771e4750d, 389c74c218d3b182e9cd767e98cee0e0fd0dabaa, ab1a602a9cea98aa37b2e6851b168d2a2633a58d, 9a53e8bd59d9f070505e51d3fd19606a270e6b93, f7e6b19bc76471ba03725fe58e0c218a3d6266c3, 36a8b2f49235e63ab3f901fe12e1b6732f075c2e, eb3d82abc335624a5e8ecfb75aba0b684e2dc4db, 4.4.233, 4.9.233, 4.14.194, 4.19.139, 5.4.58, 5.7.15, 5.8.1, 5.9, 0, 4.4.269, 4.9.269, 4.14.233, 4.19.191, 5.4.119, 5.10.37, 5.11.21, 5.12.4, 5.13

Timeline

Official Publish: February 29th, 2024
Last Modified: May 23rd, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.