PT-2021-8187 · Linux+3 · Linux Kernel+3

Aharon Landau

·

Published

2021-10-19

·

Updated

2024-11-25

·

CVE-2021-47481

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.15.0-rc4+
Description The vulnerability is related to the RDMA/mlx5 component of the Linux kernel, where the ODP xarray is not properly initialized when creating an ODP MR. This can cause a crash due to an errant set to desc size in reg create(). The issue is triggered when the mlx5 ib dereg mr() function is called, leading to a page fault and a crash. The vulnerability can be exploited to cause a denial of service.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the RDMA/mlx5 component. Specifically, update to a version later than 5.15.0-rc4+. As a temporary workaround, consider disabling the RDMA/mlx5 component until a patch is available.

Fix

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10509
CVE-2021-47481
OPENSUSE-SU-2024_2189-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse