CVE-2021-47466 affects the Linux kernel's SLUB allocator in mm/slub.c, where the error path in kmem_cache_open() can fail to release a cache's random_seq resource after initialization fails. Introduced in kernel version 4.8, the flaw can cause a memory leak and potentially degrade system availability. It carries a CVSS v3.1 score of 5.5 and requires local access with low privileges.
Upstream fixes are available in kernel versions 5.4.156, 5.10.76, 5.14.15, and 5.15 and later; the Linux kernel CVE team recommends deploying a current stable kernel rather than backporting an individual patch. Red Hat remediated affected RHEL 8 kernel and kernel-rt packages through advisories RHSA-2024:7000 and RHSA-2024:7001. RHEL 9 and its real-time kernel are not affected, while unsupported RHEL 6 and 7 deployments should be treated as potentially vulnerable unless separately mitigated or upgraded.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for the RHEL 8 kernel-rt package, addressing CVE-2021-47466.
Red Hat Bugzilla 2282890 was reported for the Linux kernel SLUB potential memory leak in kmem_cache_open().
Upstream fixes for CVE-2021-47466 were included in Linux kernel versions 5.4.156, 5.10.76, 5.14.15, and 5.15. The fix releases resources through __kmem_cache_release() when kmem_cache_open() initialization fails.
The SLUB allocator flaw was introduced in Linux kernel version 4.8 in mm/slub.c. On an initialization error path, a cache's random_seq resource could remain unreleased.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.