CVE-2021-47617
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/06/2024
Last modified:
18/09/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
PCI: pciehp: Fix infinite loop in IRQ handler upon power fault<br />
<br />
The Power Fault Detected bit in the Slot Status register differs from<br />
all other hotplug events in that it is sticky: It can only be cleared<br />
after turning off slot power. Per PCIe r5.0, sec. 6.7.1.8:<br />
<br />
If a power controller detects a main power fault on the hot-plug slot,<br />
it must automatically set its internal main power fault latch [...].<br />
The main power fault latch is cleared when software turns off power to<br />
the hot-plug slot.<br />
<br />
The stickiness used to cause interrupt storms and infinite loops which<br />
were fixed in 2009 by commits 5651c48cfafe ("PCI pciehp: fix power fault<br />
interrupt storm problem") and 99f0169c17f3 ("PCI: pciehp: enable<br />
software notification on empty slots").<br />
<br />
Unfortunately in 2020 the infinite loop issue was inadvertently<br />
reintroduced by commit 8edf5332c393 ("PCI: pciehp: Fix MSI interrupt<br />
race"): The hardirq handler pciehp_isr() clears the PFD bit until<br />
pciehp&#39;s power_fault_detected flag is set. That happens in the IRQ<br />
thread pciehp_ist(), which never learns of the event because the hardirq<br />
handler is stuck in an infinite loop. Fix by setting the<br />
power_fault_detected flag already in the hardirq handler.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.19.149 (including) | 4.19.233 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.4.69 (including) | 5.4.177 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.7 (including) | 5.10.97 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.20 (excluding) |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 5.16.6 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1db58c6584a72102e98af2e600ea184ddaf2b8af
- https://git.kernel.org/stable/c/23584c1ed3e15a6f4bfab8dc5a88d94ab929ee12
- https://git.kernel.org/stable/c/3b4c966fb156ff3e70b2526d964952ff7c1574d9
- https://git.kernel.org/stable/c/464da38ba827f670deac6500a1de9a4f0f44c41d
- https://git.kernel.org/stable/c/6d6f1f0dac3e3441ecdb1103d4efb11b9ed24dd5
- https://git.kernel.org/stable/c/ff27f7d0333cff89ec85c419f431aca1b38fb16a