CVE-2021-46918

MEDIUM

Linux Kernel 5.11-5.11.15 - Unauthenticated DMA Engine MSIX Permission Entry Persistence

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: clear MSIX permission entry on shutdown Add disabling/clearing of MSIX permission entries on device shutdown to mirror the enabling of the MSIX entries on probe. Current code left the MSIX enabled and the pasid entries still programmed at device shutdown.

Scores

CVSS v3 5.5
EPSS 0.0019
EPSS Percentile 9.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (7)
Linux/Linux < 5.11
Linux/Linux 5.11
Linux/Linux 5.11.16 - 5.11.*
Linux/Linux 5.12
Linux/Linux 8e50d392652f20616a136165dff516b86baf5e49 - 6df0e6c57dfc064af330071f372f11aa8c584997
Linux/Linux 8e50d392652f20616a136165dff516b86baf5e49 - c84b8982d7aa9b4717dc36a1c6cbc93ee153b500
linux/linux_kernel 5.11.0 - 5.11.16
Published Feb 27, 2024
Tracked Since Feb 18, 2026