CVE-2021-47101 affects the Linux kernel's ASIX USB networking driver in drivers/net/usb/asix_common.c. A short response from asix_read_cmd() in asix_mdio_read() can leave the smsr buffer uninitialized before asix_check_host_enable() uses it, potentially exposing uninitialized memory data or causing availability impacts through local exploitation. The flaw was introduced in Linux 4.9 and is fixed upstream in kernel versions 5.15.12 and 5.16 and later.
Red Hat rates the issue at CVSS 6.0, while NVD assigns 7.1. Fixes are available for standard and real-time kernels in Red Hat Enterprise Linux 8 and the standard kernel in RHEL 9, including RHEL 9.4 Extended Update Support; the RHEL 9 kernel-rt package remains affected. Organizations using ASIX USB network adapters should deploy the latest vendor-supported kernel updates rather than cherry-picking individual patches.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 standard kernel and RHSA-2024:7001 for the RHEL 8 real-time kernel to address CVE-2021-47101.
Red Hat published its record for CVE-2021-47101, describing a use-of-uninitialized-variable vulnerability in the Linux kernel ASIX USB network driver.
Red Hat released RHSA-2025:3935 to address CVE-2021-47101 in the Red Hat Enterprise Linux 9.4 Extended Update Support kernel.
Red Hat released RHSA-2024:9315 to fix CVE-2021-47101 in the standard Red Hat Enterprise Linux 9 kernel.
Linux kernel versions 5.15.12 and 5.16 fixed the ASIX asix_mdio_read() uninitialized-value condition through commits d259f621c859 and 8035b1a2a37a, respectively.
The uninitialized-value flaw in the ASIX USB networking driver's asix_mdio_read() function was introduced in Linux kernel version 4.9 by commit d9fe64e51114.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.