cbcvebase.
CVE-2021-47378
published 2024-05-21

CVE-2021-47378: In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: destroy cm id before destroy qp to avoid use after free We should always destroy…

PriorityP342critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.17%
64.1th percentile
In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: destroy cm id before destroy qp to avoid use after free We should always destroy cm_id before destroy qp to avoid to get cma event after qp was destroyed, which may lead to use after free. In RDMA connection establishment error flow, don't destroy qp in cm event handler.Just report cm_error to upper level, qp will be destroy in nvme_rdma_alloc_queue() after destroy cm id.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.14.9-1 (bookworm)linux 5.14.9-1 (bookworm)
linuxlinux
linuxlinux>= 7110230719602852481c2793d054f866b2bf4a2b < ecf0dc5a904830c926a64feffd8e01141f89822fecf0dc5a904830c926a64feffd8e01141f89822f
linuxlinux>= 7110230719602852481c2793d054f866b2bf4a2b < d268a182c56e8361e19fb781137411643312b994d268a182c56e8361e19fb781137411643312b994
linuxlinux>= 7110230719602852481c2793d054f866b2bf4a2b < 9817d763dbe15327b9b3ff4404fa6f27f927e7449817d763dbe15327b9b3ff4404fa6f27f927e744
linuxlinux_kernel< 5.10.705.10.70
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.70-15.10.70-1
linuxlinux_kernel>= 0 < 5.14.9-15.14.9-1
linuxlinux_kernel>= 0 < 5.14.9-15.14.9-1
linuxlinux_kernel>= 0 < 5.14.9-15.14.9-1
linuxlinux_kernel>= 5.11 < 5.14.95.14.9

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.