CVE-2021-47212
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2021-47212 affects the Linux kernel's net/mlx5 driver. The vulnerability was discovered in the error handling mechanism for UCTX and UMEM operations. In the fast unload flow, when the device state is set to internal error indicating the driver started the destroy process, the destroy commands incorrectly return EIO instead of MLX5_CMD_STAT_OK (Kernel Commit).

Technical details

The vulnerability exists in the MLX5 driver's command execution path where MLX5_CMD_OP_DESTROY_UCTX and MLX5_CMD_OP_DESTROY_UMEM operations incorrectly handle error states during device unload. When the device is in internal error state during fast unload, these destroy commands should return MLX5_CMD_STAT_OK but instead return EIO, causing a call trace in the umem release process (Kernel Commit).

Impact

The vulnerability results in a kernel call trace during the umem release process, which can affect system stability and potentially cause system crashes during device unload operations (Kernel Commit).

Mitigation and workarounds

The issue has been fixed in the Linux kernel by updating the error handler to return MLX5_CMD_STAT_OK instead of EIO for MLX5_CMD_OP_DESTROY_UCTX and MLX5_CMD_OP_DESTROY_UMEM operations during device unload (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64597CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • linux-aws
NoYesAug 06, 2026
CVE-2026-68480HIGH8.8
  • Linux Kernel logoLinux Kernel
  • rv
NoYesAug 06, 2026
CVE-2026-64598HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg
NoYesAug 06, 2026
CVE-2026-64604HIGH7.7
  • Linux Kernel logoLinux Kernel
  • linux-hwe-5.15
NoYesAug 06, 2026
CVE-2026-64603NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.8
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management