CVE-2021-46909
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2021-46909 is a vulnerability in the Linux kernel affecting the PCI interrupt mapping functionality. The issue was discovered in the ARM footbridge implementation where the PCI code calls the IRQ mapping function whenever a PCI driver is probed. The vulnerability was introduced by commit 30fdfb929e82 ("PCI: Add a call to pci_assign_irq() in pci_device_probe()"), which causes a kernel oops if a PCI driver is loaded or bound after the kernel has initialized (Kernel Commit).

Technical details

The vulnerability stems from IRQ mapping functions being marked with __init, which means they are removed after kernel initialization. When these functions are called later during PCI driver probing, it results in a kernel oops. The issue specifically affects the ARM footbridge architecture's PCI interrupt mapping implementation, including cats, ebsa285, netwinder, and personal server configurations (Red Hat CVE). The vulnerability has been assigned a CVSS v3 base score of 4.4 (Low) by Red Hat, with attack vector being Local, attack complexity Low, and privileges required High (Red Hat CVE).

Impact

The vulnerability only affects unusual configurations of specific CPUs and impacts the availability of some system hardware. Due to these limitations, Red Hat has classified the impact of this vulnerability as Low (Red Hat CVE).

Mitigation and workarounds

The issue has been fixed in various Linux kernel versions through patches that remove the __init markers from the IRQ mapping functions. Fixes have been implemented across multiple Linux distributions, including Ubuntu and Red Hat Enterprise Linux. For example, Ubuntu has fixed this in versions 5.4.0-74.83 for focal and 4.15.0-147.151 for bionic (Ubuntu Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt-addons
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-core
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • linux-ibm-5.15
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management