CVE-2021-47080
Severity CVSS v4.0:
Pending analysis
Type:
CWE-369
Divide By Zero
Publication date:
01/03/2024
Last modified:
09/12/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
RDMA/core: Prevent divide-by-zero error triggered by the user<br />
<br />
The user_entry_size is supplied by the user and later used as a<br />
denominator to calculate number of entries. The zero supplied by the user<br />
will trigger the following divide-by-zero error:<br />
<br />
divide error: 0000 [#1] SMP KASAN PTI<br />
CPU: 4 PID: 497 Comm: c_repro Not tainted 5.13.0-rc1+ #281<br />
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014<br />
RIP: 0010:ib_uverbs_handler_UVERBS_METHOD_QUERY_GID_TABLE+0x1b1/0x510<br />
Code: 87 59 03 00 00 e8 9f ab 1e ff 48 8d bd a8 00 00 00 e8 d3 70 41 ff 44 0f b7 b5 a8 00 00 00 e8 86 ab 1e ff 31 d2 4c 89 f0 31 ff f7 f5 48 89 d6 48 89 54 24 10 48 89 04 24 e8 1b ad 1e ff 48 8b<br />
RSP: 0018:ffff88810416f828 EFLAGS: 00010246<br />
RAX: 0000000000000008 RBX: 1ffff1102082df09 RCX: ffffffff82183f3d<br />
RDX: 0000000000000000 RSI: ffff888105f2da00 RDI: 0000000000000000<br />
RBP: ffff88810416fa98 R08: 0000000000000001 R09: ffffed102082df5f<br />
R10: ffff88810416faf7 R11: ffffed102082df5e R12: 0000000000000000<br />
R13: 0000000000000000 R14: 0000000000000008 R15: ffff88810416faf0<br />
FS: 00007f5715efa740(0000) GS:ffff88811a700000(0000) knlGS:0000000000000000<br />
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033<br />
CR2: 0000000020000840 CR3: 000000010c2e0001 CR4: 0000000000370ea0<br />
DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000<br />
DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400<br />
Call Trace:<br />
? ib_uverbs_handler_UVERBS_METHOD_INFO_HANDLES+0x4b0/0x4b0<br />
ib_uverbs_cmd_verbs+0x1546/0x1940<br />
ib_uverbs_ioctl+0x186/0x240<br />
__x64_sys_ioctl+0x38a/0x1220<br />
do_syscall_64+0x3f/0x80<br />
entry_SYSCALL_64_after_hwframe+0x44/0xae
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.10 (including) | 5.10.40 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.12.7 (excluding) |
| cpe:2.3:o:linux:linux_kernel:5.13:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.13:rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/54d87913f147a983589923c7f651f97de9af5be1
- https://git.kernel.org/stable/c/66ab7fcdac34b890017f04f391507ef5b2b89a13
- https://git.kernel.org/stable/c/e6871b4270c05f8b212e7d98aee82b357972c80a
- https://git.kernel.org/stable/c/54d87913f147a983589923c7f651f97de9af5be1
- https://git.kernel.org/stable/c/66ab7fcdac34b890017f04f391507ef5b2b89a13
- https://git.kernel.org/stable/c/e6871b4270c05f8b212e7d98aee82b357972c80a



