Red Hat addressed CVE-2021-47287, a Linux kernel driver-core flaw in drivers/base/auxiliary.c that leaks memory when driver_register() fails. In the affected __auxiliary_driver_register() path, memory allocated for auxdrv->driver.name was not released before the function returned, creating a local denial-of-service risk through resource exhaustion. Red Hat assigns the issue a CVSS 3.1 score of 5.5 (medium), with low-privilege local access required and availability as the affected security property.
The defect was introduced in Linux kernel 5.11 and fixed upstream in versions 5.13.6 and 5.14. Red Hat released fixes for affected RHEL 8 kernel and kernel-rt packages through RHSA-2024:7000 and RHSA-2024:7001; RHEL 6, 7, and 9 kernel variants are listed as not affected. Organizations running affected RHEL 8 systems should apply the advisory updates and reboot into the updated kernel; upstream recommends using the latest stable kernel release rather than cherry-picking the patch.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the affected RHEL 8 kernel and RHSA-2024:7001 for the affected RHEL 8 kernel-rt package.
Red Hat published its record for CVE-2021-47287, a low-severity Linux kernel auxiliary-bus memory leak. The issue requires local access and low privileges and is rated CVSS 3.1 5.5.
The auxiliary-bus memory leak was fixed upstream in Linux kernel 5.13.6 and 5.14. The fixes were delivered by commits ce5b3de58fc2 and 4afa0c22eed3, respectively.
A change in Linux kernel 5.11 introduced a memory leak in drivers/base/auxiliary.c: __auxiliary_driver_register() did not free auxdrv->driver.name when driver_register() failed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.