CVE-2021-46920
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2021-46920 is a vulnerability discovered in the Linux Kernel affecting the DMA engine's IDXD driver. The issue was identified where the code incorrectly handles the SWERR and OVERFLOW bits during writeback operations (Red Hat Portal, Kernel Git).

Technical details

The vulnerability stems from a flaw in the Linux Kernel's DMA engine IDXD driver where the code blindly writes over the SWERR and OVERFLOW bits. The issue occurs because the driver fails to properly handle bit operations during register writeback, potentially clobbering the OVERFLOW bit that comes after the register is read. The vulnerability has been assigned a CVSS v3 score of 4.4 (Low) by Red Hat, with an attack vector requiring local access and high privileges (Red Hat Portal).

Impact

The vulnerability has a High integrity impact but does not affect confidentiality or availability. The impact is limited by the requirement of high privileges and local access to exploit the vulnerability (Red Hat Portal).

Mitigation and workarounds

The issue has been fixed through a patch that modifies the driver to write back the bits actually read instead of blindly writing over them. The fix ensures that the driver avoids clobbering the OVERFLOW bit during register operations (Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-gcp
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-modules-extra
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management