CVE-2021-4023

low
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
2.5

Description

A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a shortage of free space. This flaw allows a local user with permissions to execute io-uring requests to possibly crash the system.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-4023

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2021-4023.html

OS impact

OSVersionStatusFixed in
arch archfixed5.15.2-1
suse slesaffected
debian debianbookwormfixed5.15.3-1
debian debianbullseyeaffected
debian debianforkyfixed5.15.3-1
debian debiansidfixed5.15.3-1
debian debiantrixiefixed5.15.3-1

References

Verify integrity in audit chain (admin only). AS-IS.