CVE-2021-47497: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells
In the Linux kernel, the following vulnerability has been resolved:
nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells
If a cell has 'nbits' equal to a multiple of BITS_PER_BYTE the logic
*p &= GENMASK((cell->nbits%BITS_PER_BYTE) - 1, 0);
will become undefined behavior because nbits modulo BITS_PER_BYTE is 0, and we
subtract one from that making a large number that is then shifted more than the
number of bits that fit into an unsigned long.
UBSAN reports this problem:
UBSAN: shift-out-of-bounds in drivers/nvmem/core.c:1386:8
shift exponent 64 is too large for 64-bit type 'unsigned long'
CPU: 6 PID: 7 Comm: kworker/u16:0 Not tainted 5.15.0-rc3+ #9
Hardware name: Google Lazor (rev3+) with KB Backlight (DT)
Workqueue: events_unbound deferred_probe_work_func
Call trace:
dump_backtrace+0x0/0x170
show_stack+0x24/0x30
dump_stack_lvl+0x64/0x7c
dump_stack+0x18/0x38
ubsan_epilogue+0x10/0x54
__ubsan_handle_shift_out_of_bounds+0x180/0x194
__nvmem_cell_read+0x1ec/0x21c
nvmem_cell_read+0x58/0x94
nvmem_cell_read_variable_common+0x4c/0xb0
nvmem_cell_read_variable_le_u32+0x40/0x100
a6xx_gpu_init+0x170/0x2f4
adreno_bind+0x174/0x284
component_bind_all+0xf0/0x264
msm_drm_bind+0x1d8/0x7a0
try_to_bring_up_master+0x164/0x1ac
__component_add+0xbc/0x13c
component_add+0x20/0x2c
dp_display_probe+0x340/0x384
platform_probe+0xc0/0x100
really_probe+0x110/0x304
__driver_probe_device+0xb8/0x120
driver_probe_device+0x4c/0xfc
__device_attach_driver+0xb0/0x128
bus_for_each_drv+0x90/0xdc
__device_attach+0xc8/0x174
device_initial_probe+0x20/0x2c
bus_probe_device+0x40/0xa4
deferred_probe_work_func+0x7c/0xb8
process_one_work+0x128/0x21c
process_scheduled_works+0x40/0x54
worker_thread+0x1ec/0x2a8
kthread+0x138/0x158
ret_from_fork+0x10/0x20
Fix it by making sure there are any bits to mask out.
Security readout for executives and security teams
Plain-English summary
CVE-2021-47497 is a Linux kernel bug in the nvmem subsystem. A byte-aligned cell size can trigger undefined shift behavior during a cell read. The public record shows it has been fixed in upstream stable commits, but provides no CVSS score, impact rating, or evidence of active exploitation.
Executive priority
Handle through normal kernel patch management unless local evidence shows crashes on affected hardware. There is no sourced evidence of exploitation or severe impact, but kernel undefined behavior should still be removed from supported fleets.
Technical view
The bug occurs when cell->nbits is a multiple of BITS_PER_BYTE. The mask calculation subtracts one after modulo returns zero, leading to a shift exponent too large for unsigned long. The cited UBSAN trace reaches __nvmem_cell_read through nvmem variable reads during device probing.
Likely exposure
Exposure is likely limited to Linux kernels with the affected nvmem code path and platform/device configurations that read byte-sized nvmem cells. The source lists Linux kernel versions and stable commits, but does not provide distribution-specific package names or a complete affected-device list.
Exploitation context
The supplied sources do not report active exploitation, KEV listing, exploit availability, remote attackability, or privilege escalation. The evidence is a UBSAN runtime fault during kernel/device initialization paths. Treat exploitability and business impact as unproven from the available public record.
Researcher notes
The record lacks CVSS, CWE, exploitability analysis, and distribution mapping. The strongest evidence is the kernel commit description and UBSAN trace. Researchers should focus on whether local kernels contain the nvmem mask guard and whether byte-aligned nvmem cells are present.
Mitigation direction
Check vendor kernel advisories for CVE-2021-47497 and applicable package updates.
Update affected Linux kernels to builds containing the referenced stable fixes.
Prioritize embedded, ChromeOS-like, or hardware-specific fleets using nvmem-backed device configuration.
Track distribution backports instead of relying only on upstream version strings.
Avoid custom kernel downgrades that remove the nvmem fix.
Validation and detection
Confirm each kernel build includes the relevant upstream stable fix commit or vendor backport.
Review kernel package changelogs for CVE-2021-47497 or the nvmem fix title.
Search system logs for UBSAN shift-out-of-bounds reports in drivers/nvmem/core.c.
Inventory devices using nvmem cell reads in board or device-tree configuration.
Validate patched kernels in hardware test coverage that exercises device probing.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2021-47497 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.