PT-2024-11157 · Linux+2 · Linux Kernel+2

Leon Romanovsky

·

Published

2021-05-10

·

Updated

2024-12-09

·

CVE-2021-47080

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.13.0-rc1+
Description A divide-by-zero error can be triggered in the Linux kernel by a user-supplied value, specifically the user entry size, which is used as a denominator to calculate the number of entries. When a zero value is supplied, it triggers a divide-by-zero error. The error occurs in the ib uverbs handler UVERBS METHOD QUERY GID TABLE function.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for this vulnerability. As a temporary workaround, consider restricting access to the ib uverbs handler UVERBS METHOD QUERY GID TABLE function until a patch is available. Avoid using the user entry size parameter with a value of zero in the affected API endpoint until the issue is resolved.

Fix

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07268
CESA-2021_4356
CVE-2021-47080
RHSA-2021:4356
RHSA-2021_4356

Affected Products

Centos
Linux Kernel
Red Hat