CVE-2021-47455 is a low-severity Linux kernel memory leak in the Precision Time Protocol (PTP) subsystem. If posix_clock_register() fails during ptp_clock_register(), a device name allocated through dev_set_name() can remain unreleased. The flaw, in drivers/ptp/ptp_clock.c, was introduced in Linux 5.5 and is resolved by calling put_device(), enabling cleanup routines to release the device name and associated memory.
The upstream fix is included in Linux 5.14.15 and 5.15, with affected stable branches receiving backports. Red Hat rated the issue CVSS 3.1 5.1 and delivered RHEL 8 kernel and kernel-rt fixes through RHSA-2024:7000 and RHSA-2024:7001; RHEL 9 kernel packages were fixed previously, while the RHEL 9 kernel-rt fix remains deferred. Organizations should deploy current vendor-supported kernel updates rather than cherry-picking the individual patch.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for the RHEL 8 kernel-rt package, remediating CVE-2021-47455.
Red Hat recorded CVE-2021-47455 as Bug 2282903, classifying the Linux kernel PTP memory-leak issue as low priority and low severity.
Red Hat released RHSA-2022:8267 to remediate CVE-2021-47455 in the Red Hat Enterprise Linux 9 kernel.
The issue was fixed in Linux kernel versions 5.14.15 and 5.15, including through commits 95c0a0c5ec88 and 4225fea1cb28. Fixes were also backported to several older stable branches.
The Linux kernel CVE team assigned CVE-2021-47455 to the PTP ptp_clock_register() memory-leak issue. The remediation adds put_device() on the registration-error path so cleanup routines can release the device name and associated PTP-clock resources.
The PTP clock-registration memory leak in drivers/ptp/ptp_clock.c was introduced in Linux 5.5 by commit a33121e5487b. On an error from posix_clock_register(), the affected path failed to release a device name allocated through dev_set_name().
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.