The Linux kernel fixed CVE-2021-47548, an array-overflow flaw in the HiSilicon HNS Ethernet driver's hns_dsaf_ge_srst_by_port() function. The function accepted port values below DSAF_GE_NUM (8) but used them to index the mac_cb array, which contains only DSAF_MAX_PORT_NUM (6) entries; values 6 and 7 could therefore access memory beyond the array and potentially cause memory corruption. The correction rejects port values greater than or equal to DSAF_MAX_PORT_NUM before the array access.
Upstream fixes are available in Linux kernel versions 4.9.292, 4.14.257, 4.19.220, 5.4.164, 5.10.84, 5.15.7, 5.16, and later stable releases. Red Hat rated the issue Moderate with CVSS 6.0, citing a network attack vector and high privileges required, and issued patched RHEL 8 and 9 kernel packages across supported update streams. The affected HNS module is supplied only on aarch64, so Red Hat x86_64 and s390x systems are unaffected.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:5101 and RHSA-2024:5102, providing fixes for CVE-2021-47548 in Red Hat Enterprise Linux 8 kernel and kernel-rt packages.
Red Hat released RHSA-2024:4902 to fix CVE-2021-47548 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
Red Hat released RHSA-2024:4740 to address CVE-2021-47548 in Red Hat Enterprise Linux 8.8 Extended Update Support.
Red Hat released RHSA-2024:4583, providing a CVE-2021-47548 fix for Red Hat Enterprise Linux 9 kernel packages.
Red Hat released fixes for CVE-2021-47548 for Red Hat Enterprise Linux 9.2 Extended Update Support through RHSA-2024:4533 and RHSA-2024:4554, covering kernel and kernel-rt packages.
The Linux kernel CVE team published an advisory for CVE-2021-47548, an out-of-bounds array access in the HiSilicon HNS Ethernet driver's hns_dsaf_ge_srst_by_port() function. The advisory explained that port values 6 and 7 could index beyond the six-entry mac_cb array and documented a bounds-check fix available in multiple stable kernel versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.