Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Linux Linux — vhost-vdpa: fix vm_flags for virtqueue doorbell mapping
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U N N H 5.5 .0023 14.2 —
AFFECTED
Product Versions Fixed
Linux ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 – —
Linux 5.8 – 5.10.36
TIMELINE
Feb 27 Reserved by Linux
Feb 27 Published (CNA: Linux)
Aug 4 RESCORED — CVE-2021-46967 (Linux). CVSS 7.8 → 5.5 (NVD).
Description
In the Linux kernel, the following vulnerability has been resolved:
vhost-vdpa: fix vm_flags for virtqueue doorbell mapping
The virtqueue doorbell is usually implemented via registeres but we
don't provide the necessary vma->flags like VM_PFNMAP. This may cause
several issues e.g when userspace tries to map the doorbell via vhost
IOTLB, kernel may panic due to the page is not backed by page
structure. This patch fixes this by setting the necessary
vm_flags. With this patch, try to map doorbell via IOTLB will fail
with bad address.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| February 27, 2024 | Reserved | Reserved by Linux |
| February 27, 2024 | Published | Published (CNA: Linux) |
| August 4, 2026 | RESCORED | RESCORED — CVE-2021-46967 (Linux). CVSS 7.8 → 5.5 (NVD). |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Linux | Linux | — | ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 | — |
| Linux | Linux | — | 5.8 | 5.10.36 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-46967 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.