CVE-2021-47284 affects the Linux kernel's mISDN Netjet ISDN driver (drivers/isdn/hardware/mISDN/netjet.c). When nj_setup fails with -EIO after the driver initializes card->irq, its cleanup routine can call free_irq for an interrupt that was never requested. This produces a kernel warning and can crash the system when panic_on_warn is enabled, creating a locally exploitable availability risk for systems using the affected hardware.
The fix removes the premature IRQ assignment and preserves assignment immediately before request_irq. Fixed Linux stable releases include 4.4.273, 4.9.273, 4.14.237, 4.19.195, 5.4.126, 5.10.44, 5.12.11, and 5.13; organizations should deploy a current stable kernel. Red Hat rated the issue Low severity (CVSS 3.1: 5.5) and issued fixes for RHEL 8 kernel and kernel-rt; RHEL 9 is not affected, while RHEL 6 and 7 are out of support.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat fixed CVE-2021-47284 in Red Hat Enterprise Linux 8 kernel and kernel-rt updates through advisories RHSA-2024:5101 and RHSA-2024:5102. The issue can cause a denial of service when the Netjet driver's probe error path frees an unrequested IRQ.
The Linux kernel CVE team assigned CVE-2021-47284 to an mISDN Netjet driver flaw in which error handling can free an IRQ that was never requested, potentially causing a kernel panic. Fixes were incorporated into stable kernel versions 4.4.273, 4.9.273, 4.14.237, 4.19.195, 5.4.126, 5.10.44, 5.12.11, and 5.13.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.