
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-46920 is a vulnerability discovered in the Linux Kernel affecting the DMA engine's IDXD driver. The issue was identified where the code incorrectly handles the SWERR and OVERFLOW bits during writeback operations (Red Hat Portal, Kernel Git).
The vulnerability stems from a flaw in the Linux Kernel's DMA engine IDXD driver where the code blindly writes over the SWERR and OVERFLOW bits. The issue occurs because the driver fails to properly handle bit operations during register writeback, potentially clobbering the OVERFLOW bit that comes after the register is read. The vulnerability has been assigned a CVSS v3 score of 4.4 (Low) by Red Hat, with an attack vector requiring local access and high privileges (Red Hat Portal).
The vulnerability has a High integrity impact but does not affect confidentiality or availability. The impact is limited by the requirement of high privileges and local access to exploit the vulnerability (Red Hat Portal).
The issue has been fixed through a patch that modifies the driver to write back the bits actually read instead of blindly writing over them. The fix ensures that the driver avoids clobbering the OVERFLOW bit during register operations (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."