octeontx2-pf: fix a buffer overflow in otx2_set_rxfh_context()
Published Mar 25, 2024
7.8
HIGHCVSS 3.1
EPSS 0.24%
Description
This function is called from ethtool_set_rxfh() and "*rss_context" comes from the user. Add some bounds checking to prevent memory corruption.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.12
- Version 5.12.9StatusunaffectedConstraints<=5.12.*
- Version 5.13StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.12 · < 5.12.9
- 5.13
- 5.13
- 5.13
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
References (8)
- https://access.redhat.com/security/cve/CVE-2021-47148 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2271495 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-33796 Advisory
- https://git.kernel.org/stable/c/389146bc6d2bbb20714d06624b74856320ce40f7 Patch
- https://git.kernel.org/stable/c/e5cc361e21648b75f935f9571d4003aaee480214 Patch
- https://lore.kernel.org/linux-cve-announce/2024032559-CVE-2021-47148-502f@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2021-47148
- https://www.cve.org/CVERecord?id=CVE-2021-47148
Change history (0)
No recorded changes yet.