GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel mlx5_core kTLS RX offload: TLS RX resync list corruption: entries are moved by the resync handler

CVE-2021-47215Kernel, userspace & hypervisornet/mlx5e kTLS crash in RX resync flowcurated

Impact

TLS RX resync list corruption: entries are moved by the resync handler while still in use in NAPI, corrupting the list from the receive softirq. Remote and unauthenticated on any node using mlx5 hardware kTLS RX offload.

Who can reach it

Remote sender over a TLS connection handled by mlx5 kTLS RX offload, able to trigger resync conditions (out-of-order or retransmitted TLS records).

What to do

Upgrade the host kernel to 5.16 or the 5.15.5 stable backport. Rolling reboot. Interim: disable kTLS RX offload (ethtool -K <dev> tls-hw-rx-offload off) as a live config change.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.