CVE-2021-47265

MEDIUM

Linux Kernel - Unauthenticated Denial of Service via RDMA Flow Rule Port Validation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA: Verify port when creating flow rule Validate port value provided by the user and with that remove no longer needed validation by the driver. The missing check in the mlx5_ib driver could cause to the below oops. Call trace: _create_flow_rule+0x2d4/0xf28 [mlx5_ib] mlx5_ib_create_flow+0x2d0/0x5b0 [mlx5_ib] ib_uverbs_ex_create_flow+0x4cc/0x624 [ib_uverbs] ib_uverbs_handler_UVERBS_METHOD_INVOKE_WRITE+0xd4/0x150 [ib_uverbs] ib_uverbs_cmd_verbs.isra.7+0xb28/0xc50 [ib_uverbs] ib_uverbs_ioctl+0x158/0x1d0 [ib_uverbs] do_vfs_ioctl+0xd0/0xaf0 ksys_ioctl+0x84/0xb4 __arm64_sys_ioctl+0x28/0xc4 el0_svc_common.constprop.3+0xa4/0x254 el0_svc_handler+0x84/0xa0 el0_svc+0x10/0x26c Code: b9401260 f9615681 51000400 8b001c20 (f9403c1a)

Scores

CVSS v3 5.5
EPSS 0.0020
EPSS Percentile 9.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (8)
Linux/Linux < 3.12
Linux/Linux 3.12
Linux/Linux 436f2ad05a0b65b1467ddf51bc68171c381bf844 - 2adcb4c5a52a2623cd2b43efa7041e74d19f3a5e
Linux/Linux 436f2ad05a0b65b1467ddf51bc68171c381bf844 - 8dc1b0e0ca204596c50bcd159ee069ae0f998176
Linux/Linux 5.12.11 - 5.12.*
Linux/Linux 5.13
linux/linux_kernel 5.13 rc1 (5 CPE variants)
linux/linux_kernel 3.12 - 5.12.11
Published May 21, 2024
Tracked Since Feb 18, 2026