LiveActive security incident?Get immediate response
CVE Record

CVE-2021-47497: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells

In the Linux kernel, the following vulnerability has been resolved: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells If a cell has 'nbits' equal to a multiple of BITS_PER_BYTE the logic *p &= GENMASK((cell->nbits%BITS_PER_BYTE) - 1, 0); will become undefined behavior because nbits modulo BITS_PER_BYTE is 0, and we subtract one from that making a large number that is then shifted more than the number of bits that fit into an unsigned long. UBSAN reports this problem: UBSAN: shift-out-of-bounds in drivers/nvmem/core.c:1386:8 shift exponent 64 is too large for 64-bit type 'unsigned long' CPU: 6 PID: 7 Comm: kworker/u16:0 Not tainted 5.15.0-rc3+ #9 Hardware name: Google Lazor (rev3+) with KB Backlight (DT) Workqueue: events_unbound deferred_probe_work_func Call trace: dump_backtrace+0x0/0x170 show_stack+0x24/0x30 dump_stack_lvl+0x64/0x7c dump_stack+0x18/0x38 ubsan_epilogue+0x10/0x54 __ubsan_handle_shift_out_of_bounds+0x180/0x194 __nvmem_cell_read+0x1ec/0x21c nvmem_cell_read+0x58/0x94 nvmem_cell_read_variable_common+0x4c/0xb0 nvmem_cell_read_variable_le_u32+0x40/0x100 a6xx_gpu_init+0x170/0x2f4 adreno_bind+0x174/0x284 component_bind_all+0xf0/0x264 msm_drm_bind+0x1d8/0x7a0 try_to_bring_up_master+0x164/0x1ac __component_add+0xbc/0x13c component_add+0x20/0x2c dp_display_probe+0x340/0x384 platform_probe+0xc0/0x100 really_probe+0x110/0x304 __driver_probe_device+0xb8/0x120 driver_probe_device+0x4c/0xfc __device_attach_driver+0xb0/0x128 bus_for_each_drv+0x90/0xdc __device_attach+0xc8/0x174 device_initial_probe+0x20/0x2c bus_probe_device+0x40/0xa4 deferred_probe_work_func+0x7c/0xb8 process_one_work+0x128/0x21c process_scheduled_works+0x40/0x54 worker_thread+0x1ec/0x2a8 kthread+0x138/0x158 ret_from_fork+0x10/0x20 Fix it by making sure there are any bits to mask out.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2021-47497 is a Linux kernel bug in the nvmem subsystem. A byte-aligned cell size can trigger undefined shift behavior during a cell read. The public record shows it has been fixed in upstream stable commits, but provides no CVSS score, impact rating, or evidence of active exploitation.

Executive priority

Handle through normal kernel patch management unless local evidence shows crashes on affected hardware. There is no sourced evidence of exploitation or severe impact, but kernel undefined behavior should still be removed from supported fleets.

Technical view

The bug occurs when cell->nbits is a multiple of BITS_PER_BYTE. The mask calculation subtracts one after modulo returns zero, leading to a shift exponent too large for unsigned long. The cited UBSAN trace reaches __nvmem_cell_read through nvmem variable reads during device probing.

Likely exposure

Exposure is likely limited to Linux kernels with the affected nvmem code path and platform/device configurations that read byte-sized nvmem cells. The source lists Linux kernel versions and stable commits, but does not provide distribution-specific package names or a complete affected-device list.

Exploitation context

The supplied sources do not report active exploitation, KEV listing, exploit availability, remote attackability, or privilege escalation. The evidence is a UBSAN runtime fault during kernel/device initialization paths. Treat exploitability and business impact as unproven from the available public record.

Researcher notes

The record lacks CVSS, CWE, exploitability analysis, and distribution mapping. The strongest evidence is the kernel commit description and UBSAN trace. Researchers should focus on whether local kernels contain the nvmem mask guard and whether byte-aligned nvmem cells are present.

Mitigation direction

  • Check vendor kernel advisories for CVE-2021-47497 and applicable package updates.
  • Update affected Linux kernels to builds containing the referenced stable fixes.
  • Prioritize embedded, ChromeOS-like, or hardware-specific fleets using nvmem-backed device configuration.
  • Track distribution backports instead of relying only on upstream version strings.
  • Avoid custom kernel downgrades that remove the nvmem fix.

Validation and detection

  • Confirm each kernel build includes the relevant upstream stable fix commit or vendor backport.
  • Review kernel package changelogs for CVE-2021-47497 or the nvmem fix title.
  • Search system logs for UBSAN shift-out-of-bounds reports in drivers/nvmem/core.c.
  • Inventory devices using nvmem cell reads in board or device-tree configuration.
  • Validate patched kernels in hardware test coverage that exercises device probing.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-47497 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
9Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux69aba7948cbe53f2f1827e84e9dd0ae470a5072e, 69aba7948cbe53f2f1827e84e9dd0ae470a5072e, 69aba7948cbe53f2f1827e84e9dd0ae470a5072e, 69aba7948cbe53f2f1827e84e9dd0ae470a5072e, 69aba7948cbe53f2f1827e84e9dd0ae470a5072e, 69aba7948cbe53f2f1827e84e9dd0ae470a5072e, 69aba7948cbe53f2f1827e84e9dd0ae470a5072e, 69aba7948cbe53f2f1827e84e9dd0ae470a5072eunaffected
LinuxLinux4.3, 0, 4.4.290, 4.9.288, 4.14.252, 4.19.213, 5.4.155, 5.10.75, 5.14.14, 5.15affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.