PT-2021-8187 · Linux+3 · Linux Kernel+3
Aharon Landau
·
Published
2021-10-19
·
Updated
2024-11-25
·
CVE-2021-47481
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.15.0-rc4+
Description
The vulnerability is related to the RDMA/mlx5 component of the Linux kernel, where the ODP xarray is not properly initialized when creating an ODP MR. This can cause a crash due to an errant set to
desc size in reg create(). The issue is triggered when the mlx5 ib dereg mr() function is called, leading to a page fault and a crash. The vulnerability can be exploited to cause a denial of service.Recommendations
To resolve the issue, update the Linux kernel to a version that includes the fix for the RDMA/mlx5 component. Specifically, update to a version later than 5.15.0-rc4+.
As a temporary workaround, consider disabling the RDMA/mlx5 component until a patch is available.
Fix
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Red Os
Suse