
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-47481 affects the Linux kernel's RDMA/mlx5 driver, specifically related to the initialization of ODP xarray when creating an ODP MR. The vulnerability was discovered in 2021 and affects Linux kernel systems using the mlx5 RDMA driver (Kernel Git).
The vulnerability stems from a missing initialization of the ODP xarray when creating an ODP MR in the mlx5 RDMA driver. While normally zero fill would hide this missing initialization, an errant set to desc_size in reg_create() causes a system crash. This results in a page fault at address 0x0000000800000000, leading to a kernel oops (Kernel Git).
When exploited, this vulnerability can cause a system crash (kernel oops) in affected Linux systems using the mlx5 RDMA driver. The crash occurs during memory registration operations, specifically during MR deregistration (Kernel Git).
The vulnerability can be triggered through the RDMA user-space interface when performing memory registration operations. It has been demonstrated to cause system crashes in testing environments (Kernel Git).
The fix involves adding the missing xarray initialization and removing the desc_size set in the affected code. This was addressed through a patch that initializes the implicit_children xarray when creating an ODP MR (Kernel Git).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."