CVE-2021-47289 is a moderate-severity Linux kernel flaw in ACPI device reference handling. A code path introduced by commit 71f642833284 could invoke acpi_dev_put() with a NULL pointer, leading the helper to call put_device() using an invalid offset and potentially crash the host. Red Hat assigned a CVSS v3.1 score of 5.5, reflecting low-complexity local exploitation with high availability impact.
Upstream fixed the issue by making acpi_dev_put() safely handle NULL pointers; fixes are included in kernel versions 5.4.139, 5.10.57, 5.13.6, and 5.14 and later stable releases. Red Hat remediated affected RHEL 8 kernel and kernel-rt packages through RHSA-2024:7000 and RHSA-2024:7001, while RHEL 6 and 7 are outside support scope and should be treated as vulnerable unless otherwise mitigated.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for the RHEL 8 kernel-rt package to address CVE-2021-47289. Red Hat rated the locally triggerable ACPI NULL-pointer dereference as Moderate, with a CVSS v3.1 score of 5.5.
The Linux kernel CVE team assigned CVE-2021-47289 to an ACPI reference-counting flaw in which acpi_dev_put() could receive a NULL pointer and trigger an invalid put_device() call. Upstream fixes make acpi_dev_put() safely accept NULL pointers and are included in kernel versions 5.4.139, 5.10.57, 5.13.6, and 5.14.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.