CVE-2021-47131 (GCVE-0-2021-47131)
Vulnerability from cvelistv5
Published
2024-03-15 20:14
Modified
2026-08-05 08:46
Summary
In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix use-after-free after the TLS device goes down and up When a netdev with active TLS offload goes down, tls_device_down is called to stop the offload and tear down the TLS context. However, the socket stays alive, and it still points to the TLS context, which is now deallocated. If a netdev goes up, while the connection is still active, and the data flow resumes after a number of TCP retransmissions, it will lead to a use-after-free of the TLS context. This commit addresses this bug by keeping the context alive until its normal destruction, and implements the necessary fallbacks, so that the connection can resume in software (non-offloaded) kTLS mode. On the TX side tls_sw_fallback is used to encrypt all packets. The RX side already has all the necessary fallbacks, because receiving non-decrypted packets is supported. The thing needed on the RX side is to block resync requests, which are normally produced after receiving non-decrypted packets. The necessary synchronization is implemented for a graceful teardown: first the fallbacks are deployed, then the driver resources are released (it used to be possible to have a tls_dev_resync after tls_dev_del). A new flag called TLS_RX_DEV_DEGRADED is added to indicate the fallback mode. It's used to skip the RX resync logic completely, as it becomes useless, and some objects may be released (for example, resync_async, which is allocated and freed by the driver).
Impacted products
Vendor Product Version
Linux Linux Version: e8f69799810c32dd40c6724d829eccc70baad07f
Version: e8f69799810c32dd40c6724d829eccc70baad07f
Version: e8f69799810c32dd40c6724d829eccc70baad07f
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2021-47131",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-03-19T15:23:46.487605Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-04T17:14:12.171Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-04T05:24:39.881Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/f1d4184f128dede82a59a841658ed40d4e6d3aa2"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/0f1e6fe66977a864fe850522316f713d7b926fd9"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/c55dcdd435aa6c6ad6ccac0a4c636d010ee367a4"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "include/net/tls.h",
            "net/tls/tls_device.c",
            "net/tls/tls_device_fallback.c",
            "net/tls/tls_main.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "f1d4184f128dede82a59a841658ed40d4e6d3aa2",
              "status": "affected",
              "version": "e8f69799810c32dd40c6724d829eccc70baad07f",
              "versionType": "git"
            },
            {
              "lessThan": "0f1e6fe66977a864fe850522316f713d7b926fd9",
              "status": "affected",
              "version": "e8f69799810c32dd40c6724d829eccc70baad07f",
              "versionType": "git"
            },
            {
              "lessThan": "c55dcdd435aa6c6ad6ccac0a4c636d010ee367a4",
              "status": "affected",
              "version": "e8f69799810c32dd40c6724d829eccc70baad07f",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "include/net/tls.h",
            "net/tls/tls_device.c",
            "net/tls/tls_device_fallback.c",
            "net/tls/tls_main.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.18"
            },
            {
              "lessThan": "4.18",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.43",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.12.*",
              "status": "unaffected",
              "version": "5.12.10",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "5.13",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.43",
                  "versionStartIncluding": "4.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.12.10",
                  "versionStartIncluding": "4.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.13",
                  "versionStartIncluding": "4.18",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tls: Fix use-after-free after the TLS device goes down and up\n\nWhen a netdev with active TLS offload goes down, tls_device_down is\ncalled to stop the offload and tear down the TLS context. However, the\nsocket stays alive, and it still points to the TLS context, which is now\ndeallocated. If a netdev goes up, while the connection is still active,\nand the data flow resumes after a number of TCP retransmissions, it will\nlead to a use-after-free of the TLS context.\n\nThis commit addresses this bug by keeping the context alive until its\nnormal destruction, and implements the necessary fallbacks, so that the\nconnection can resume in software (non-offloaded) kTLS mode.\n\nOn the TX side tls_sw_fallback is used to encrypt all packets. The RX\nside already has all the necessary fallbacks, because receiving\nnon-decrypted packets is supported. The thing needed on the RX side is\nto block resync requests, which are normally produced after receiving\nnon-decrypted packets.\n\nThe necessary synchronization is implemented for a graceful teardown:\nfirst the fallbacks are deployed, then the driver resources are released\n(it used to be possible to have a tls_dev_resync after tls_dev_del).\n\nA new flag called TLS_RX_DEV_DEGRADED is added to indicate the fallback\nmode. It\u0027s used to skip the RX resync logic completely, as it becomes\nuseless, and some objects may be released (for example, resync_async,\nwhich is allocated and freed by the driver)."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The UAF is reached when a remote TLS peer sends data on an existing kTLS hardware-offloaded TCP connection after the NIC flaps, hitting net/tls RX resync paths that dereference driver state freed by tls_dev_del.\nAC:H - Exploitation requires the offload netdev to go down and back up while the connection stays alive, which a remote peer cannot force; once that state exists, sending traffic reliably triggers the bug.\nPR:N - A remote TLS client or peer needs no local account or privileges\u2014only an established connection to a host using kTLS device offload (for example HTTPS with NIC TLS offload).\nUI:N - No additional user action is required beyond ordinary connection and data transfer after the device cycle; the attacker does not need a victim to open a file or click anything.\nS:U - Impact is confined to the host kernel that owns the TLS offload context; this is standard kernel memory corruption without a VM/IOMMU or other security-authority boundary cross.\nC:H - Use-after-free of the driver RX resync object (and related offload state) enables heap reuse and arbitrary read primitives per UAF scoring guidance.\nI:H - The same UAF is exploitable for heap spray and control-flow hijacking/arbitrary write, and the missing TX fallback can also mishandle post-teardown xmit state.\nA:H - Dereferencing freed resync_async or calling tls_dev_resync after tls_dev_del can oops/panic the kernel, so availability impact is High."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T08:46:13.224Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f1d4184f128dede82a59a841658ed40d4e6d3aa2"
        },
        {
          "url": "https://git.kernel.org/stable/c/0f1e6fe66977a864fe850522316f713d7b926fd9"
        },
        {
          "url": "https://git.kernel.org/stable/c/c55dcdd435aa6c6ad6ccac0a4c636d010ee367a4"
        }
      ],
      "title": "net/tls: Fix use-after-free after the TLS device goes down and up",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2021-47131",
    "datePublished": "2024-03-15T20:14:34.647Z",
    "dateReserved": "2024-03-04T18:12:48.840Z",
    "dateUpdated": "2026-08-05T08:46:13.224Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/f1d4184f128dede82a59a841658ed40d4e6d3aa2\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/0f1e6fe66977a864fe850522316f713d7b926fd9\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/c55dcdd435aa6c6ad6ccac0a4c636d010ee367a4\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-04T05:24:39.881Z\"}}, {\"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2021-47131\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-03-19T15:23:46.487605Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-05-23T19:01:18.760Z\"}, \"title\": \"CISA ADP Vulnrichment\"}], \"cna\": {\"title\": \"net/tls: Fix use-after-free after the TLS device goes down and up\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 8.1, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - The UAF is reached when a remote TLS peer sends data on an existing kTLS hardware-offloaded TCP connection after the NIC flaps, hitting net/tls RX resync paths that dereference driver state freed by tls_dev_del.\\nAC:H - Exploitation requires the offload netdev to go down and back up while the connection stays alive, which a remote peer cannot force; once that state exists, sending traffic reliably triggers the bug.\\nPR:N - A remote TLS client or peer needs no local account or privileges\\u2014only an established connection to a host using kTLS device offload (for example HTTPS with NIC TLS offload).\\nUI:N - No additional user action is required beyond ordinary connection and data transfer after the device cycle; the attacker does not need a victim to open a file or click anything.\\nS:U - Impact is confined to the host kernel that owns the TLS offload context; this is standard kernel memory corruption without a VM/IOMMU or other security-authority boundary cross.\\nC:H - Use-after-free of the driver RX resync object (and related offload state) enables heap reuse and arbitrary read primitives per UAF scoring guidance.\\nI:H - The same UAF is exploitable for heap spray and control-flow hijacking/arbitrary write, and the missing TX fallback can also mishandle post-teardown xmit state.\\nA:H - Dereferencing freed resync_async or calling tls_dev_resync after tls_dev_del can oops/panic the kernel, so availability impact is High.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"e8f69799810c32dd40c6724d829eccc70baad07f\", \"lessThan\": \"f1d4184f128dede82a59a841658ed40d4e6d3aa2\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"e8f69799810c32dd40c6724d829eccc70baad07f\", \"lessThan\": \"0f1e6fe66977a864fe850522316f713d7b926fd9\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"e8f69799810c32dd40c6724d829eccc70baad07f\", \"lessThan\": \"c55dcdd435aa6c6ad6ccac0a4c636d010ee367a4\", \"versionType\": \"git\"}], \"programFiles\": [\"include/net/tls.h\", \"net/tls/tls_device.c\", \"net/tls/tls_device_fallback.c\", \"net/tls/tls_main.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.18\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.18\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.10.43\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.12.10\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.12.*\"}, {\"status\": \"unaffected\", \"version\": \"5.13\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"include/net/tls.h\", \"net/tls/tls_device.c\", \"net/tls/tls_device_fallback.c\", \"net/tls/tls_main.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/f1d4184f128dede82a59a841658ed40d4e6d3aa2\"}, {\"url\": \"https://git.kernel.org/stable/c/0f1e6fe66977a864fe850522316f713d7b926fd9\"}, {\"url\": \"https://git.kernel.org/stable/c/c55dcdd435aa6c6ad6ccac0a4c636d010ee367a4\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nnet/tls: Fix use-after-free after the TLS device goes down and up\\n\\nWhen a netdev with active TLS offload goes down, tls_device_down is\\ncalled to stop the offload and tear down the TLS context. However, the\\nsocket stays alive, and it still points to the TLS context, which is now\\ndeallocated. If a netdev goes up, while the connection is still active,\\nand the data flow resumes after a number of TCP retransmissions, it will\\nlead to a use-after-free of the TLS context.\\n\\nThis commit addresses this bug by keeping the context alive until its\\nnormal destruction, and implements the necessary fallbacks, so that the\\nconnection can resume in software (non-offloaded) kTLS mode.\\n\\nOn the TX side tls_sw_fallback is used to encrypt all packets. The RX\\nside already has all the necessary fallbacks, because receiving\\nnon-decrypted packets is supported. The thing needed on the RX side is\\nto block resync requests, which are normally produced after receiving\\nnon-decrypted packets.\\n\\nThe necessary synchronization is implemented for a graceful teardown:\\nfirst the fallbacks are deployed, then the driver resources are released\\n(it used to be possible to have a tls_dev_resync after tls_dev_del).\\n\\nA new flag called TLS_RX_DEV_DEGRADED is added to indicate the fallback\\nmode. It\u0027s used to skip the RX resync logic completely, as it becomes\\nuseless, and some objects may be released (for example, resync_async,\\nwhich is allocated and freed by the driver).\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.43\", \"versionStartIncluding\": \"4.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.12.10\", \"versionStartIncluding\": \"4.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.13\", \"versionStartIncluding\": \"4.18\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T08:46:13.224Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2021-47131\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T08:46:13.224Z\", \"dateReserved\": \"2024-03-04T18:12:48.840Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-03-15T20:14:34.647Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…