CVE-2021-47383 is a moderate-severity out-of-bounds read flaw in the Linux kernel framebuffer-console (tty) subsystem's imageblit function. A local low-privileged process can trigger invalid vmalloc memory access through an FBIOPUT_VSCREENINFO ioctl request containing only partially populated fb_var_screeninfo fields, including xres, yres, and bits_per_pixel. If the requested configuration matches the prior request, the kernel can skip resize_screen(), leaving display values incomplete and producing incorrect row and coordinate calculations that lead to the invalid access, system crashes, or instability.
The upstream fix forces resize_screen() to populate the structure even where no display resize is needed; corrected releases span kernel versions from 4.4.286 through 5.15. Red Hat rated the issue CVSS 6.6 (CWE-125) and issued fixes for affected RHEL 8, RHEL 9, and RHEL 9.2 Extended Update Support kernel packages. Organizations should deploy updated kernel packages; no practical workaround was identified. RHEL 9 kernel-rt remained affected in the advisory, while RHEL 7 packages were outside support scope.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for the RHEL 8 kernel-rt package, addressing CVE-2021-47383.
Red Hat released RHSA-2024:5364 for the RHEL 9.2 Extended Update Support kernel and RHSA-2024:5365 for its kernel-rt variant, fixing CVE-2021-47383.
Red Hat released RHSA-2024:8617, fixing CVE-2021-47383 in the RHEL 9 kernel. The RHEL 9 kernel-rt package remained listed as affected without a corresponding erratum.
Linux kernel stable releases 4.4.286, 4.9.285, 4.14.249, 4.19.209, 5.4.151, 5.10.71, 5.14.10, and 5.15 incorporated fixes for CVE-2021-47383. The remediation ensures resize_screen() completes fb_var_screeninfo even when a display resize is not required, preventing the out-of-bounds vmalloc access in imageblit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.