cbcvebase.
CVE-2021-47001
published 2024-02-28

CVE-2021-47001: In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix cwnd update ordering After a reconnect, the reply handler is opening the cwnd…

PriorityP418medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.74%
51.4th percentile
In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix cwnd update ordering After a reconnect, the reply handler is opening the cwnd (and thus enabling more RPC Calls to be sent) /before/ rpcrdma_post_recvs() can post enough Receive WRs to receive their replies. This causes an RNR and the new connection is lost immediately. The race is most clearly exposed when KASAN and disconnect injection are enabled. This slows down rpcrdma_rep_create() enough to allow the send side to post a bunch of RPC Calls before the Receive completion handler can invoke ib_post_recv().

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 2ae50ad68cd79224198b525f7bd645c9da98b6ff < eddae8be7944096419c2ae29477a45f767d0fcd4eddae8be7944096419c2ae29477a45f767d0fcd4
linuxlinux>= 2ae50ad68cd79224198b525f7bd645c9da98b6ff < 8834ecb5df22b7ff3c9b0deba7726579bb613f958834ecb5df22b7ff3c9b0deba7726579bb613f95
linuxlinux>= 2ae50ad68cd79224198b525f7bd645c9da98b6ff < 19b5fa9489b5706bc878c3a522a7f771079e2fa019b5fa9489b5706bc878c3a522a7f771079e2fa0
linuxlinux>= 2ae50ad68cd79224198b525f7bd645c9da98b6ff < 35d8b10a25884050bb3b0149b62c3818ec59f77c35d8b10a25884050bb3b0149b62c3818ec59f77c
linuxlinux>= 5.4.13 < 5.55.5
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.4.0-204.2245.4.0-204.224
linuxlinux_kernel>= 5.11 < 5.11.225.11.22
linuxlinux_kernel>= 5.12 < 5.12.55.12.5
linuxlinux_kernel>= 5.5 < 5.10.385.10.38

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.