CVE-2021-47616 (GCVE-0-2021-47616)
Vulnerability from cvelistv5
Published
2024-06-19 14:58
Modified
2026-08-05 08:48
Summary
In the Linux kernel, the following vulnerability has been resolved: RDMA: Fix use-after-free in rxe_queue_cleanup On error handling path in rxe_qp_from_init() qp->sq.queue is freed and then rxe_create_qp() will drop last reference to this object. qp clean up function will try to free this queue one time and it causes UAF bug. Fix it by zeroing queue pointer after freeing queue in rxe_qp_from_init().
Impacted products
Vendor Product Version
Linux Linux Version: 514aee660df493cd673154a6ba6bab745ec47b8c
Version: 514aee660df493cd673154a6ba6bab745ec47b8c
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-04T05:47:40.519Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/acb53e47db1fbc7cd37ab10b46388f045a76e383"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/84b01721e8042cdd1e8ffeb648844a09cd4213e0"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2021-47616",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T17:11:45.722005Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:34:50.651Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/sw/rxe/rxe_qp.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "acb53e47db1fbc7cd37ab10b46388f045a76e383",
              "status": "affected",
              "version": "514aee660df493cd673154a6ba6bab745ec47b8c",
              "versionType": "git"
            },
            {
              "lessThan": "84b01721e8042cdd1e8ffeb648844a09cd4213e0",
              "status": "affected",
              "version": "514aee660df493cd673154a6ba6bab745ec47b8c",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/sw/rxe/rxe_qp.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "lessThan": "5.15",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.10",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "5.16",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.10",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.16",
                  "versionStartIncluding": "5.15",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA: Fix use-after-free in rxe_queue_cleanup\n\nOn error handling path in rxe_qp_from_init() qp-\u003esq.queue is freed and\nthen rxe_create_qp() will drop last reference to this object. qp clean up\nfunction will try to free this queue one time and it causes UAF bug.\n\nFix it by zeroing queue pointer after freeing queue in rxe_qp_from_init()."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The bug is triggered through local RDMA uverbs create-QP (ioctl/write on /dev/infiniband/uverbsN) or local rdma netlink newlink during SoftRoCE device setup, not by processing unauthenticated remote packets.\nAC:L - An attacker who can create a QP can reliably force the rxe_qp_init_resp failure path after a successful send-queue init (e.g., ENOMEM on the receive queue), causing the double free without depending on races or other conditions outside their control.\nPR:L - Ordinary RC/UC/UD QP creation needs no capabilities, and uverbs nodes are created mode 0666; once an rxe device exists (typical SoftRoCE deployment), an unprivileged local user can open it and hit the bug. Creating the device itself only needs CAP_NET_ADMIN, which is also obtainable in a user+net namespace.\nUI:N - Exploitation requires only attacker-controlled syscalls; no victim action such as mounting a filesystem or opening a malicious file is needed.\nS:U - This is standard kernel heap corruption leading to privilege escalation within the same host security authority, with no VM escape or IOMMU/cross-boundary impact.\nC:H - The vulnerability is a use-after-free/double-free of the send queue object; per kernel UAF guidance this enables reclaim of the freed object and arbitrary kernel memory disclosure.\nI:H - Double-free of the kmalloc\u0027d rxe_queue (and associated buffer) is classic heap corruption that can be turned into arbitrary write / control-flow hijacking via heap shaping.\nA:H - The UAF reliably produces a kernel oops/crash (as seen in the syzbot KASAN report in rxe_queue_cleanup), so availability impact is High."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T08:48:39.530Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/acb53e47db1fbc7cd37ab10b46388f045a76e383"
        },
        {
          "url": "https://git.kernel.org/stable/c/84b01721e8042cdd1e8ffeb648844a09cd4213e0"
        }
      ],
      "title": "RDMA: Fix use-after-free in rxe_queue_cleanup",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2021-47616",
    "datePublished": "2024-06-19T14:58:03.817Z",
    "dateReserved": "2024-06-19T14:55:32.795Z",
    "dateUpdated": "2026-08-05T08:48:39.530Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/acb53e47db1fbc7cd37ab10b46388f045a76e383\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/84b01721e8042cdd1e8ffeb648844a09cd4213e0\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-04T05:47:40.519Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2021-47616\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T17:11:45.722005Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:26.281Z\"}}], \"cna\": {\"title\": \"RDMA: Fix use-after-free in rxe_queue_cleanup\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The bug is triggered through local RDMA uverbs create-QP (ioctl/write on /dev/infiniband/uverbsN) or local rdma netlink newlink during SoftRoCE device setup, not by processing unauthenticated remote packets.\\nAC:L - An attacker who can create a QP can reliably force the rxe_qp_init_resp failure path after a successful send-queue init (e.g., ENOMEM on the receive queue), causing the double free without depending on races or other conditions outside their control.\\nPR:L - Ordinary RC/UC/UD QP creation needs no capabilities, and uverbs nodes are created mode 0666; once an rxe device exists (typical SoftRoCE deployment), an unprivileged local user can open it and hit the bug. Creating the device itself only needs CAP_NET_ADMIN, which is also obtainable in a user+net namespace.\\nUI:N - Exploitation requires only attacker-controlled syscalls; no victim action such as mounting a filesystem or opening a malicious file is needed.\\nS:U - This is standard kernel heap corruption leading to privilege escalation within the same host security authority, with no VM escape or IOMMU/cross-boundary impact.\\nC:H - The vulnerability is a use-after-free/double-free of the send queue object; per kernel UAF guidance this enables reclaim of the freed object and arbitrary kernel memory disclosure.\\nI:H - Double-free of the kmalloc\u0027d rxe_queue (and associated buffer) is classic heap corruption that can be turned into arbitrary write / control-flow hijacking via heap shaping.\\nA:H - The UAF reliably produces a kernel oops/crash (as seen in the syzbot KASAN report in rxe_queue_cleanup), so availability impact is High.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"514aee660df493cd673154a6ba6bab745ec47b8c\", \"lessThan\": \"acb53e47db1fbc7cd37ab10b46388f045a76e383\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"514aee660df493cd673154a6ba6bab745ec47b8c\", \"lessThan\": \"84b01721e8042cdd1e8ffeb648844a09cd4213e0\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/infiniband/sw/rxe/rxe_qp.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.15\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.15\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.15.10\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"5.16\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/infiniband/sw/rxe/rxe_qp.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/acb53e47db1fbc7cd37ab10b46388f045a76e383\"}, {\"url\": \"https://git.kernel.org/stable/c/84b01721e8042cdd1e8ffeb648844a09cd4213e0\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nRDMA: Fix use-after-free in rxe_queue_cleanup\\n\\nOn error handling path in rxe_qp_from_init() qp-\u003esq.queue is freed and\\nthen rxe_create_qp() will drop last reference to this object. qp clean up\\nfunction will try to free this queue one time and it causes UAF bug.\\n\\nFix it by zeroing queue pointer after freeing queue in rxe_qp_from_init().\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.10\", \"versionStartIncluding\": \"5.15\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.16\", \"versionStartIncluding\": \"5.15\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T08:48:39.530Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2021-47616\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T08:48:39.530Z\", \"dateReserved\": \"2024-06-19T14:55:32.795Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-06-19T14:58:03.817Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…