CVE-2021-47061 - CVE House
Back to Database
Status published High CVE-2021-47061

KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: KVM: Destroy I/O bus devices on unregister failure _after_ sync'ing SRCU If allocating a new instance of an I/O bus fails when unregistering a device, wait to destroy the device until after all readers are guaranteed to see the new null bus. Destroying devices before the bus is nullified could lead to use-after-free since readers expect the devices on their reference of the bus to remain valid.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47061

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
f65886606c2d3b562716de030706dfe1bea4ed5e, f0dfffce3f4ffd5f822568a4a6fb34c010e939d1, 840e124f89a5127e7eb97ebf377f4b8ca745c070, 40a023f681befd9b2862a3c16fb306a38b359ae5, 19184bd06f488af62924ff1747614a8cb284ad63, 41b2ea7a6a11e2b1a7f2c29e1675a709a6b2b98d, 68c125324b5e1d1d22805653735442923d896a1d, 4.4.238, 4.9.238, 4.14.200, 4.19.148, 5.4.66, 5.8.10, 5.9, 0, 5.10.37, 5.11.21, 5.12.4, 5.13

Timeline

Official Publish: February 29th, 2024
Last Modified: May 23rd, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.