
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-47212 affects the Linux kernel's net/mlx5 driver. The vulnerability was discovered in the error handling mechanism for UCTX and UMEM operations. In the fast unload flow, when the device state is set to internal error indicating the driver started the destroy process, the destroy commands incorrectly return EIO instead of MLX5_CMD_STAT_OK (Kernel Commit).
The vulnerability exists in the MLX5 driver's command execution path where MLX5_CMD_OP_DESTROY_UCTX and MLX5_CMD_OP_DESTROY_UMEM operations incorrectly handle error states during device unload. When the device is in internal error state during fast unload, these destroy commands should return MLX5_CMD_STAT_OK but instead return EIO, causing a call trace in the umem release process (Kernel Commit).
The vulnerability results in a kernel call trace during the umem release process, which can affect system stability and potentially cause system crashes during device unload operations (Kernel Commit).
The issue has been fixed in the Linux kernel by updating the error handler to return MLX5_CMD_STAT_OK instead of EIO for MLX5_CMD_OP_DESTROY_UCTX and MLX5_CMD_OP_DESTROY_UMEM operations during device unload (Kernel Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."