CVE-2021-47138
published 2024-03-25CVE-2021-47138: In the Linux kernel, the following vulnerability has been resolved: cxgb4: avoid accessing registers when clearing filters Hardware register having the server…
PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.24%
15.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
cxgb4: avoid accessing registers when clearing filters
Hardware register having the server TID base can contain
invalid values when adapter is in bad state (for example,
due to AER fatal error). Reading these invalid values in the
register can lead to out-of-bound memory access. So, fix
by using the saved server TID base when clearing filters.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= b1a79360ee862f8ada4798ad2346fa45bb41b527 < 0bf49b3c8d8b3a43ce09f1b2db70e5484d31fcdf | 0bf49b3c8d8b3a43ce09f1b2db70e5484d31fcdf |
| linux | linux | >= b1a79360ee862f8ada4798ad2346fa45bb41b527 < 02f03883fdb10ad7e66717c70ea163a8d27ae6e7 | 02f03883fdb10ad7e66717c70ea163a8d27ae6e7 |
| linux | linux | >= b1a79360ee862f8ada4798ad2346fa45bb41b527 < 285207a558ab456aa7d8aa877ecc7e91fcc51710 | 285207a558ab456aa7d8aa877ecc7e91fcc51710 |
| linux | linux | >= b1a79360ee862f8ada4798ad2346fa45bb41b527 < 88c380df84fbd03f9b137c2b9d0a44b9f2f553b0 | 88c380df84fbd03f9b137c2b9d0a44b9f2f553b0 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.46-1 | 5.10.46-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 5.11 < 5.12.9 | 5.12.9 |
| linux | linux_kernel | >= 5.2 < 5.4.124 | 5.4.124 |
| linux | linux_kernel | >= 5.5 < 5.10.42 | 5.10.42 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: cxgb4: avoid accessing registers when clearing filters
vendor_redhat·2024-03-25·CVSS 7.1
CVE-2021-47138 [HIGH] CWE-125 kernel: cxgb4: avoid accessing registers when clearing filters
kernel: cxgb4: avoid accessing registers when clearing filters
In the Linux kernel, the following vulnerability has been resolved:
cxgb4: avoid accessing registers when clearing filters
Hardware register having the server TID base can contain
invalid values when adapter is in bad state (for example,
due to AER fatal error). Reading these invalid values in the
register can lead to out-of-bound memory access. So, fix
by using the saved server TID base when clearing filters.
A vulnerability was found in the Linux kernel whereby hardware registries that have the server TID base may contain invalid values when the adapter is in a bad state. Reading these invalid values can result in out-of-bounds memory access, which can cause memory corruption or crashes.
Statement: Red Hat believes this vu
Debian
CVE-2021-47138: linux - In the Linux kernel, the following vulnerability has been resolved: cxgb4: avoi...
vendor_debian·2021·CVSS 7.1
CVE-2021-47138 [HIGH] CVE-2021-47138: linux - In the Linux kernel, the following vulnerability has been resolved: cxgb4: avoi...
In the Linux kernel, the following vulnerability has been resolved: cxgb4: avoid accessing registers when clearing filters Hardware register having the server TID base can contain invalid values when adapter is in bad state (for example, due to AER fatal error). Reading these invalid values in the register can lead to out-of-bound memory access. So, fix by using the saved server TID base when clearing filters.
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.46-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
GHSA
GHSA-qjmm-w6cw-3hf3: In the Linux kernel, the following vulnerability has been resolved:
cxgb4: avoid accessing registers when clearing filters
Hardware register having
ghsa_unreviewed·2024-03-25
CVE-2021-47138 [HIGH] CWE-787 GHSA-qjmm-w6cw-3hf3: In the Linux kernel, the following vulnerability has been resolved:
cxgb4: avoid accessing registers when clearing filters
Hardware register having
In the Linux kernel, the following vulnerability has been resolved:
cxgb4: avoid accessing registers when clearing filters
Hardware register having the server TID base can contain
invalid values when adapter is in bad state (for example,
due to AER fatal error). Reading these invalid values in the
register can lead to out-of-bound memory access. So, fix
by using the saved server TID base when clearing filters.
OSV
CVE-2021-47138: In the Linux kernel, the following vulnerability has been resolved: cxgb4: avoid accessing registers when clearing filters Hardware register having th
osv·2024-03-25·CVSS 7.1
CVE-2021-47138 [HIGH] CVE-2021-47138: In the Linux kernel, the following vulnerability has been resolved: cxgb4: avoid accessing registers when clearing filters Hardware register having th
In the Linux kernel, the following vulnerability has been resolved: cxgb4: avoid accessing registers when clearing filters Hardware register having the server TID base can contain invalid values when adapter is in bad state (for example, due to AER fatal error). Reading these invalid values in the register can lead to out-of-bound memory access. So, fix by using the saved server TID base when clearing filters.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/02f03883fdb10ad7e66717c70ea163a8d27ae6e7https://git.kernel.org/stable/c/0bf49b3c8d8b3a43ce09f1b2db70e5484d31fcdfhttps://git.kernel.org/stable/c/285207a558ab456aa7d8aa877ecc7e91fcc51710https://git.kernel.org/stable/c/88c380df84fbd03f9b137c2b9d0a44b9f2f553b0https://git.kernel.org/stable/c/02f03883fdb10ad7e66717c70ea163a8d27ae6e7https://git.kernel.org/stable/c/0bf49b3c8d8b3a43ce09f1b2db70e5484d31fcdfhttps://git.kernel.org/stable/c/285207a558ab456aa7d8aa877ecc7e91fcc51710https://git.kernel.org/stable/c/88c380df84fbd03f9b137c2b9d0a44b9f2f553b0
2024-03-25
Published