{"id":"DEBIAN-CVE-2021-47391","details":"In the Linux kernel, the following vulnerability has been resolved:  RDMA/cma: Ensure rdma_addr_cancel() happens before issuing more requests  The FSM can run in a circle allowing rdma_resolve_ip() to be called twice on the same id_priv. While this cannot happen without going through the work, it violates the invariant that the same address resolution background request cannot be active twice.         CPU 1                                  CPU 2  rdma_resolve_addr():   RDMA_CM_IDLE -\u003e RDMA_CM_ADDR_QUERY   rdma_resolve_ip(addr_handler)  #1  \t\t\t process_one_req(): for #1                           addr_handler():                             RDMA_CM_ADDR_QUERY -\u003e RDMA_CM_ADDR_BOUND                             mutex_unlock(&id_priv-\u003ehandler_mutex);                             [.. handler still running ..]  rdma_resolve_addr():   RDMA_CM_ADDR_BOUND -\u003e RDMA_CM_ADDR_QUERY   rdma_resolve_ip(addr_handler)     !! two requests are now on the req_list  rdma_destroy_id():  destroy_id_handler_unlock():   _destroy_id():    cma_cancel_operation():     rdma_addr_cancel()                            // process_one_req() self removes it \t\t          spin_lock_bh(&lock);                            cancel_delayed_work(&req-\u003ework); \t                   if (!list_empty(&req-\u003elist)) == true        ! rdma_addr_cancel() returns after process_on_req #1 is done     kfree(id_priv)  \t\t\t process_one_req(): for #2                           addr_handler(): \t                    mutex_lock(&id_priv-\u003ehandler_mutex);                             !! Use after free on id_priv  rdma_addr_cancel() expects there to be one req on the list and only cancels the first one. The self-removal behavior of the work only happens after the handler has returned. This yields a situations where the req_list can have two reqs for the same \"handle\" but rdma_addr_cancel() only cancels the first one.  The second req remains active beyond rdma_destroy_id() and will use-after-free id_priv once it inevitably triggers.  Fix this by remembering if the id_priv has called rdma_resolve_ip() and always cancel before calling it again. This ensures the req_list never gets more than one item in it and doesn't cost anything in the normal flow that never uses this strange error path.","modified":"2026-09-15T09:02:39.981235829Z","published":"2024-05-21T15:15:24.480Z","upstream":["CVE-2021-47391"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47391"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47391.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47391.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47391.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}