CVE-2021-47468 affects the Linux kernel's mISDN NetJet ISDN driver, where card->isac.release() can be invoked while a lock is held in an atomic context. Because the release path may sleep, a local attacker able to exercise the affected device-removal path could trigger a kernel fault or denial of service. The upstream fix defers the release-function call until after the lock has been released.
The fix was backported to stable kernels including 4.4.290, 4.9.288, 4.14.253, 4.19.214, 5.4.156, 5.10.76, 5.14.15, and 5.15. Red Hat rated the flaw Low severity (CVSS 4.4) and released RHEL 8 kernel updates through advisories including RHSA-2024:5101 and RHSA-2024:5102; RHEL 9 is not affected. Organizations should deploy their vendor's current kernel updates rather than cherry-picking the upstream patch.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:5101 and RHSA-2024:5102 to address CVE-2021-47468 in Red Hat Enterprise Linux 8 kernel and kernel-rt streams.
Red Hat issued RHSA-2024:6993 to fix CVE-2021-47468 for Red Hat Enterprise Linux 8.8 Extended Update Support.
Red Hat issued RHSA-2024:5692 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions, addressing CVE-2021-47468.
The Linux kernel CVE team assigned CVE-2021-47468 to a flaw in the mISDN NetJet ISDN driver where card->isac.release() could invoke sleeping work while an atomic-context lock was held. Upstream remediation moved the release-function call until after the relevant lock was released.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.