CVE-2021-47097 is a stack out-of-bounds read in the Linux kernel's Elantech input-device driver. During Elantech/PS/2 mouse initialization, elantech_change_report_id() supplied a two-byte param[] buffer to the PSMOUSE_CMD_GETINFO path, which accesses three bytes; KASAN confirmed the invalid stack access. A local attacker may be able to crash the host or disclose internal kernel information. The upstream fix expands the buffer to three bytes.
Affected upstream release lines include Linux 5.4 before 5.4.169, 5.10 before 5.10.89, and releases from 5.11 before fixes in 5.15.12 and 5.16. Red Hat rates the flaw as moderate severity with CVSS 6.0, while NVD assigns 7.1. Red Hat issued fixes for RHEL 8 kernel and kernel-rt through RHSA-2024:7000 and RHSA-2024:7001; its advisory lists RHEL 9 kernel and kernel-rt as affected, requiring appropriate updated kernel packages when available.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for the RHEL 8 kernel-rt package, remediating CVE-2021-47097. RHEL 9 kernel and kernel-rt remained listed as affected.
Zack Miele reported the CVE-2021-47097 vulnerability record to Red Hat's tracking system.
The Linux kernel CVE team published CVE-2021-47097 for a one-byte stack out-of-bounds read in the Elantech driver's elantech_change_report_id() function. The disclosed fix expands the local param[] array from two bytes to three bytes; fixed kernel releases include 5.4.169, 5.10.89, 5.15.12, and 5.16.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.