CVE-2021-47215

CRITICAL

Linux Kernel 5.13-5.15.4 - Denial of Service via TLS RX Resync List Corruption

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix crash in RX resync flow For the TLS RX resync flow, we maintain a list of TLS contexts that require some attention, to communicate their resync information to the HW. Here we fix list corruptions, by protecting the entries against movements coming from resync_handle_seq_match(), until their resync handling in napi is fully completed.

Scores

CVSS v3 9.8
EPSS 0.0049
EPSS Percentile 39.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (8)
Linux/Linux < 5.13
Linux/Linux 5.13
Linux/Linux 5.15.5 - 5.15.*
Linux/Linux 5.16
Linux/Linux e9ce991bce5bacf71641bd0f72f4b7c589529f40 - cc4a9cc03faa6d8db1a6954bb536f2c1e63bdff6
Linux/Linux e9ce991bce5bacf71641bd0f72f4b7c589529f40 - ebeda7a9528ae690e6bf12791a868f0cca8391f2
linux/linux_kernel 5.16 rc1
linux/linux_kernel 5.13 - 5.15.5
Published Apr 10, 2024
Tracked Since Feb 18, 2026