CVE-2021-47497 affects the Linux kernel NVMEM subsystem's cell-read masking logic when a cell's nbits value is an exact multiple of BITS_PER_BYTE. A modulo-zero calculation can be decremented before use, producing an invalid shift exponent—reported by UBSAN as a 64-bit shift on a 64-bit system—and causing undefined behavior. The flaw was introduced in Linux 4.3 and is primarily associated with availability impact under Red Hat's assessment.
Upstream fixed the issue in stable kernel releases including 4.4.290, 4.9.288, 4.14.252, 4.19.213, 5.4.155, 5.10.75, 5.14.14, and 5.15; the kernel CVE team advises upgrading to a current stable release rather than cherry-picking patches. Red Hat rated the issue Low (CVSS 3.1: 4.4), issued fixes for RHEL 8 standard and real-time kernels and the RHEL 9 standard kernel, and lists the RHEL 9 kernel-rt package as affected without a corresponding erratum.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for the RHEL 8 real-time kernel, addressing CVE-2021-47497.
Red Hat released RHSA-2025:2490, fixing CVE-2021-47497 for the RHEL 9.4 Extended Update Support kernel.
Red Hat released RHSA-2024:9315 to address CVE-2021-47497 in the standard RHEL 9 kernel.
Fixes for CVE-2021-47497 were included in stable kernel releases 4.4.290, 4.9.288, 4.14.252, 4.19.213, 5.4.155, 5.10.75, 5.14.14, and 5.15. The Linux kernel CVE team recommended upgrading to a current stable release rather than cherry-picking individual commits.
The Linux kernel CVE team assigned CVE-2021-47497 to the NVMEM out-of-bounds shift issue in drivers/nvmem/core.c. The fix checks that bits remain to be masked before applying the mask operation.
The vulnerable NVMEM cell-read masking logic was introduced by commit 69aba7948cbe in Linux kernel 4.3. When a cell bit count is an exact multiple of BITS_PER_BYTE, the calculation can produce an invalid shift parameter and trigger undefined behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.