cbcvebase.
CVE-2021-47015
published 2024-02-28

CVE-2021-47015: In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix RX consumer index logic in the error path. In bnxt_rx_pkt(), the RX buffers…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.4th percentile
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix RX consumer index logic in the error path. In bnxt_rx_pkt(), the RX buffers are expected to complete in order. If the RX consumer index indicates an out of order buffer completion, it means we are hitting a hardware bug and the driver will abort all remaining RX packets and reset the RX ring. The RX consumer index that we pass to bnxt_discard_rx() is not correct. We should be passing the current index (tmp_raw_cons) instead of the old index (raw_cons). This bug can cause us to be at the wrong index when trying to abort the next RX packet. It can crash like this: #0 [ffff9bbcdf5c39a8] machine_kexec at ffffffff9b05e007 #1 [ffff9bbcdf5c3a00] __crash_kexec at ffffffff9b111232 #2 [ffff9bbcdf5c3ad0] panic at ffffffff9b07d61e #3 [ffff9bbcdf5c3b50] oops_end at ffffffff9b030978 #4 [ffff9bbcdf5c3b78] no_context at ffffffff9b06aaf0 #5 [ffff9bbcdf5c3bd8] __bad_area_nosemaphore at ffffffff9b06ae2e #6 [ffff9bbcdf5c3c28] bad_area_nosemaphore at ffffffff9b06af24 #7 [ffff9bbcdf5c3c38] __do_page_fault at ffffffff9b06b67e #8 [ffff9bbcdf5c3cb0] do_page_fault at ffffffff9b06bb12 #9 [ffff9bbcdf5c3ce0] page_fault at ffffffff9bc015c5 [exception RIP: bnxt_rx_pkt+237] RIP: ffffffffc0259cdd RSP: ffff9bbcdf5c3d98 RFLAGS: 00010213 RAX: 000000005dd8097f RBX: ffff9ba4cb11b7e0 RCX: ffffa923cf6e9000 RDX: 0000000000000fff RSI: 0000000000000627 RDI: 0000000000001000 RBP: ffff9bbcdf5c3e60 R8: 0000000000420003 R9: 000000000000020d R10: ffffa923cf6ec138 R11: ffff9bbcdf5c3e83 R12: ffff9ba4d6f928c0 R13: ffff9ba4cac28080 R14: ffff9ba4cb11b7f0 R15: ffff9ba4d5a30000 ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.112 < 4.154.15
linuxlinux>= 4.19.35 < 4.204.20
linuxlinux>= 4.9.169 < 4.104.10
linuxlinux>= 5.0.8 < 5.15.1
linuxlinux>= a1b0e4e684e9c300b9e759b46cb7a0147e61ddff < b1523e4ba293b2a32d9fabaf70c1dcaa6e3e2847b1523e4ba293b2a32d9fabaf70c1dcaa6e3e2847
linuxlinux>= a1b0e4e684e9c300b9e759b46cb7a0147e61ddff < 4fcaad2b7dac3f16704f8118c7e481024ddbd3ed4fcaad2b7dac3f16704f8118c7e481024ddbd3ed
linuxlinux>= a1b0e4e684e9c300b9e759b46cb7a0147e61ddff < e187ef83c04a5d23e68d39cfdff1a1931e29890ce187ef83c04a5d23e68d39cfdff1a1931e29890c
linuxlinux>= a1b0e4e684e9c300b9e759b46cb7a0147e61ddff < 3fbc5bc651d688fbea2a59cdc91520a2f5334d0a3fbc5bc651d688fbea2a59cdc91520a2f5334d0a
linuxlinux>= a1b0e4e684e9c300b9e759b46cb7a0147e61ddff < bbd6f0a948139970f4a615dff189d9a503681a39bbd6f0a948139970f4a615dff189d9a503681a39
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 5.1 < 5.4.1195.4.119
linuxlinux_kernel>= 5.11 < 5.11.215.11.21
linuxlinux_kernel>= 5.12 < 5.12.45.12.4
linuxlinux_kernel>= 5.5 < 5.10.375.10.37

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.