CVE-2021-47321 is a use-after-free flaw in Linux kernel watchdog drivers. During driver removal, affected code used del_timer(), which could return while an active timer handler continued running; the handler could then access memory freed with the driver, causing system instability or crashes. The upstream fix replaces it with del_timer_sync(), ensuring the handler has finished and cannot reschedule before resources are released.
The correction is included in Linux kernel versions 4.4.276, 4.9.276, 4.14.240, 4.19.198, 5.4.134, 5.10.52, 5.12.19, 5.13.4, 5.14, and later stable releases. Red Hat rated the issue Moderate (CVSS 3.1: 4.4) and issued RHEL 8 and RHEL 8.8 Extended Update Support fixes through RHSA-2024:7000, RHSA-2024:7001, and RHSA-2024:8107; RHEL 9 is not affected. Organizations should update affected kernel and kernel-rt packages, as Red Hat identified no practical mitigation.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for the RHEL 8 kernel-rt package, addressing CVE-2021-47321.
Red Hat published its record for CVE-2021-47321, a Linux watchdog-driver use-after-free caused by remove paths using del_timer() without waiting for active timer handlers. The upstream fix replaces del_timer() with del_timer_sync().
Red Hat released RHSA-2024:8107 to fix CVE-2021-47321 in the Red Hat Enterprise Linux 8.8 Extended Update Support kernel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.