---
id: CVE-2021-4001
title: >-
  A race condition was found in the Linux kernel's ebpf verifier between
  bpf_map_update_elem and bpf_map_freeze due to a missing lock in
  kernel/bpf/syscall.c
summary: >-
  A race condition was found in the Linux kernel's ebpf verifier between
  bpf_map_update_elem and bpf_map_freeze due to a missing lock in
  kernel/bpf/syscall.c. In this flaw, a local user with a special privilege
  (cap_sys_admin or cap_bpf) c…
severity: medium
cvss: 4.1
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-367
  - CWE-367
vendor: linux
product: linux_kernel
affected:
  - linux_kernel <= 5.15
  - linux_kernel = 5.16
published: '2022-01-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:42.587'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-4001'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2025645'
    label: secalert@redhat.com
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=353050be4c19e102178ccc05988101887c25ae53
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2025645'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=353050be4c19e102178ccc05988101887c25ae53
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00186
epssPercentile: 0.07549
ingestedAt: '2026-10-08T22:11:53.744Z'
---

## Overview

A race condition was found in the Linux kernel's ebpf verifier between bpf_map_update_elem and bpf_map_freeze due to a missing lock in kernel/bpf/syscall.c. In this flaw, a local user with a special privilege (cap_sys_admin or cap_bpf) can modify the frozen mapped address space. This flaw affects kernel versions prior to 5.16 rc2.

## Affected

- `linux_kernel <= 5.15`
- `linux_kernel = 5.16`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
