CVE-2021-47137
published 2024-03-25CVE-2021-47137: In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where memory allocation or dma…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: lantiq: fix memory corruption in RX ring
In a situation where memory allocation or dma mapping fails, an
invalid address is programmed into the descriptor. This can lead
to memory corruption. If the memory allocation fails, DMA should
reuse the previous skb and mapping and drop the packet. This patch
also increments rx drop counter.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= fe1a56420cf2ec28c8eceef672b87de0bbe1a260 < 8bb1077448d43a871ed667520763e3b9f9b7975d | 8bb1077448d43a871ed667520763e3b9f9b7975d |
| linux | linux | >= fe1a56420cf2ec28c8eceef672b87de0bbe1a260 < 5ac72351655f8b033a2935646f53b7465c903418 | 5ac72351655f8b033a2935646f53b7465c903418 |
| linux | linux | >= fe1a56420cf2ec28c8eceef672b87de0bbe1a260 < 46dd4abced3cb2c912916f4a5353e0927db0c4a2 | 46dd4abced3cb2c912916f4a5353e0927db0c4a2 |
| linux | linux | >= fe1a56420cf2ec28c8eceef672b87de0bbe1a260 < c7718ee96dbc2f9c5fc3b578abdf296dd44b9c20 | c7718ee96dbc2f9c5fc3b578abdf296dd44b9c20 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 4.20 < 5.4.124 | 5.4.124 |
| linux | linux_kernel | >= 5.11 < 5.12.9 | 5.12.9 |
| linux | linux_kernel | >= 5.5 < 5.10.42 | 5.10.42 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: lantiq: fix memory corruption in RX ring
vendor_redhat·2024-03-25·CVSS 7.8
CVE-2021-47137 [HIGH] CWE-99 kernel: net: lantiq: fix memory corruption in RX ring
kernel: net: lantiq: fix memory corruption in RX ring
In the Linux kernel, the following vulnerability has been resolved:
net: lantiq: fix memory corruption in RX ring
In a situation where memory allocation or dma mapping fails, an
invalid address is programmed into the descriptor. This can lead
to memory corruption. If the memory allocation fails, DMA should
reuse the previous skb and mapping and drop the packet. This patch
also increments rx drop counter.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat
Debian
CVE-2021-47137: linux - In the Linux kernel, the following vulnerability has been resolved: net: lantiq...
vendor_debian·2021·CVSS 7.8
CVE-2021-47137 [HIGH] CVE-2021-47137: linux - In the Linux kernel, the following vulnerability has been resolved: net: lantiq...
In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where memory allocation or dma mapping fails, an invalid address is programmed into the descriptor. This can lead to memory corruption. If the memory allocation fails, DMA should reuse the previous skb and mapping and drop the packet. This patch also increments rx drop counter.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.46-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
GHSA
GHSA-x7cq-pgcc-cqqm: In the Linux kernel, the following vulnerability has been resolved:
net: lantiq: fix memory corruption in RX ring
In a situation where memory alloca
ghsa_unreviewed·2024-03-25
CVE-2021-47137 [HIGH] CWE-770 GHSA-x7cq-pgcc-cqqm: In the Linux kernel, the following vulnerability has been resolved:
net: lantiq: fix memory corruption in RX ring
In a situation where memory alloca
In the Linux kernel, the following vulnerability has been resolved:
net: lantiq: fix memory corruption in RX ring
In a situation where memory allocation or dma mapping fails, an
invalid address is programmed into the descriptor. This can lead
to memory corruption. If the memory allocation fails, DMA should
reuse the previous skb and mapping and drop the packet. This patch
also increments rx drop counter.
OSV
CVE-2021-47137: In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where memory allocati
osv·2024-03-25·CVSS 7.8
CVE-2021-47137 [HIGH] CVE-2021-47137: In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where memory allocati
In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where memory allocation or dma mapping fails, an invalid address is programmed into the descriptor. This can lead to memory corruption. If the memory allocation fails, DMA should reuse the previous skb and mapping and drop the packet. This patch also increments rx drop counter.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/46dd4abced3cb2c912916f4a5353e0927db0c4a2https://git.kernel.org/stable/c/5ac72351655f8b033a2935646f53b7465c903418https://git.kernel.org/stable/c/8bb1077448d43a871ed667520763e3b9f9b7975dhttps://git.kernel.org/stable/c/c7718ee96dbc2f9c5fc3b578abdf296dd44b9c20https://git.kernel.org/stable/c/46dd4abced3cb2c912916f4a5353e0927db0c4a2https://git.kernel.org/stable/c/5ac72351655f8b033a2935646f53b7465c903418https://git.kernel.org/stable/c/8bb1077448d43a871ed667520763e3b9f9b7975dhttps://git.kernel.org/stable/c/c7718ee96dbc2f9c5fc3b578abdf296dd44b9c20
2024-03-25
Published