CVE-2021-47386 is a NULL-pointer dereference in the Linux kernel's w83791d hardware-monitoring driver. Device-provided values can trigger a read path that dereferences an obsolete lm75[] structure field, causing a kernel crash and resulting in a local denial of service. The field was no longer needed after the driver moved subclient detection to devm_i2c_new_dummy_device().
The issue was identified by the Linux Driver Verification project and fixed in kernel versions 5.4.151, 5.10.71, 5.14.10, and 5.15 and later. Red Hat rates the flaw Moderate (CVSS 4.4), requiring local high privileges with availability-only impact; fixes are available in affected RHEL 8 and RHEL 9 kernel packages, while RHEL 9 kernel-rt is marked will not fix and RHEL 6 and 7 are outside support scope.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat fixed CVE-2021-47386 in the RHEL 8 kernel through RHSA-2024:7000 and in the RHEL 8 kernel-rt package through RHSA-2024:7001.
Red Hat fixed CVE-2021-47386 for the RHEL 9.4 Extended Update Support kernel through RHSA-2025:4509.
Red Hat fixed CVE-2021-47386 in the RHEL 9 kernel through RHSA-2024:9315.
The fix removes the unnecessary lm75[] field from the w83791d driver. It was incorporated into Linux kernel versions 5.4.151, 5.10.71, 5.14.10, and 5.15.
The Linux kernel CVE team assigned CVE-2021-47386 to the NULL pointer dereference in drivers/hwmon/w83791d.c, which could crash the kernel and cause denial of service.
The Linux Driver Verification project found that the w83791d hardware-monitoring driver could dereference a NULL pointer when processing specific device-provided values. The flaw was caused by an obsolete lm75[] structure field left after the driver changed its subclient handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.