CVE-2021-46917
published 2024-02-27CVE-2021-46917: In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq cleanup of WQCFG registers A pre-release silicon erratum workaround…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.22%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: fix wq cleanup of WQCFG registers
A pre-release silicon erratum workaround where wq reset does not clear
WQCFG registers was leaked into upstream code. Use wq reset command
instead of blasting the MMIO region. This also address an issue where
we clobber registers in future devices.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.38-1 (bookworm) | linux 5.10.38-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 5.7.10 < 5.8 | 5.8 |
| linux | linux | >= da32b28c95a79e399e18c03f8178f41aec9c66e4 < e5eb9757fe4c2392e069246ae78badc573af1833 | e5eb9757fe4c2392e069246ae78badc573af1833 |
| linux | linux | >= da32b28c95a79e399e18c03f8178f41aec9c66e4 < f7dc8f5619165e1fa3383d0c2519f502d9e2a1a9 | f7dc8f5619165e1fa3383d0c2519f502d9e2a1a9 |
| linux | linux | >= da32b28c95a79e399e18c03f8178f41aec9c66e4 < ea9aadc06a9f10ad20a90edc0a484f1147d88a7a | ea9aadc06a9f10ad20a90edc0a484f1147d88a7a |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 0 < 5.10.38-1 | 5.10.38-1 |
| linux | linux_kernel | >= 5.11.0 < 5.11.16 | 5.11.16 |
| linux | linux_kernel | >= 5.8.0 < 5.10.32 | 5.10.32 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: wq reset does not clear WQCFG registers
vendor_redhat·2024-02-27·CVSS 5.5
CVE-2021-46917 [MEDIUM] CWE-402 kernel: wq reset does not clear WQCFG registers
kernel: wq reset does not clear WQCFG registers
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: fix wq cleanup of WQCFG registers
A pre-release silicon erratum workaround where wq reset does not clear
WQCFG registers was leaked into upstream code. Use wq reset command
instead of blasting the MMIO region. This also address an issue where
we clobber registers in future devices.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Affected
Package: kernel (Red Hat Enterprise Linux 9) - Affected
Package: kernel-rt (Re
Debian
CVE-2021-46917: linux - In the Linux kernel, the following vulnerability has been resolved: dmaengine: ...
vendor_debian·2021·CVSS 5.5
CVE-2021-46917 [MEDIUM] CVE-2021-46917: linux - In the Linux kernel, the following vulnerability has been resolved: dmaengine: ...
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq cleanup of WQCFG registers A pre-release silicon erratum workaround where wq reset does not clear WQCFG registers was leaked into upstream code. Use wq reset command instead of blasting the MMIO region. This also address an issue where we clobber registers in future devices.
Scope: local
bookworm: resolved (fixed in 5.10.38-1)
bullseye: resolved (fixed in 5.10.38-1)
forky: resolved (fixed in 5.10.38-1)
sid: resolved (fixed in 5.10.38-1)
trixie: resolved (fixed in 5.10.38-1)
OSV
CVE-2021-46917: In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq cleanup of WQCFG registers A pre-release silicon erratum w
osv·2024-02-27·CVSS 5.5
CVE-2021-46917 [MEDIUM] CVE-2021-46917: In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq cleanup of WQCFG registers A pre-release silicon erratum w
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix wq cleanup of WQCFG registers A pre-release silicon erratum workaround where wq reset does not clear WQCFG registers was leaked into upstream code. Use wq reset command instead of blasting the MMIO region. This also address an issue where we clobber registers in future devices.
GHSA
GHSA-79cc-r4hf-5pv4: In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: fix wq cleanup of WQCFG registers
A pre-release silicon erratum
ghsa_unreviewed·2024-02-27
CVE-2021-46917 [MEDIUM] CWE-668 GHSA-79cc-r4hf-5pv4: In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: fix wq cleanup of WQCFG registers
A pre-release silicon erratum
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: fix wq cleanup of WQCFG registers
A pre-release silicon erratum workaround where wq reset does not clear
WQCFG registers was leaked into upstream code. Use wq reset command
instead of blasting the MMIO region. This also address an issue where
we clobber registers in future devices.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/e5eb9757fe4c2392e069246ae78badc573af1833https://git.kernel.org/stable/c/ea9aadc06a9f10ad20a90edc0a484f1147d88a7ahttps://git.kernel.org/stable/c/f7dc8f5619165e1fa3383d0c2519f502d9e2a1a9https://git.kernel.org/stable/c/e5eb9757fe4c2392e069246ae78badc573af1833https://git.kernel.org/stable/c/ea9aadc06a9f10ad20a90edc0a484f1147d88a7ahttps://git.kernel.org/stable/c/f7dc8f5619165e1fa3383d0c2519f502d9e2a1a9
2024-02-27
Published