{"id":"DEBIAN-CVE-2021-47399","details":"In the Linux kernel, the following vulnerability has been resolved:  ixgbe: Fix NULL pointer dereference in ixgbe_xdp_setup  The ixgbe driver currently generates a NULL pointer dereference with some machine (online cpus \u003c 63). This is due to the fact that the maximum value of num_xdp_queues is nr_cpu_ids. Code is in \"ixgbe_set_rss_queues\"\".  Here's how the problem repeats itself: Some machine (online cpus \u003c 63), And user set num_queues to 63 through ethtool. Code is in the \"ixgbe_set_channels\", \tadapter-\u003ering_feature[RING_F_FDIR].limit = count;  It becomes 63.  When user use xdp, \"ixgbe_set_rss_queues\" will set queues num. \tadapter-\u003enum_rx_queues = rss_i; \tadapter-\u003enum_tx_queues = rss_i; \tadapter-\u003enum_xdp_queues = ixgbe_xdp_queues(adapter);  And rss_i's value is from \tf = &adapter-\u003ering_feature[RING_F_FDIR]; \trss_i = f-\u003eindices = f-\u003elimit;  So \"num_rx_queues\" \u003e \"num_xdp_queues\", when run to \"ixgbe_xdp_setup\", \tfor (i = 0; i \u003c adapter-\u003enum_rx_queues; i++) \t\tif (adapter-\u003exdp_ring[i]-\u003exsk_umem)  It leads to panic.  Call trace: [exception RIP: ixgbe_xdp+368] RIP: ffffffffc02a76a0  RSP: ffff9fe16202f8d0  RFLAGS: 00010297 RAX: 0000000000000000  RBX: 0000000000000020  RCX: 0000000000000000 RDX: 0000000000000000  RSI: 000000000000001c  RDI: ffffffffa94ead90 RBP: ffff92f8f24c0c18   R8: 0000000000000000   R9: 0000000000000000 R10: ffff9fe16202f830  R11: 0000000000000000  R12: ffff92f8f24c0000 R13: ffff9fe16202fc01  R14: 000000000000000a  R15: ffffffffc02a7530 ORIG_RAX: ffffffffffffffff  CS: 0010  SS: 0018  7 [ffff9fe16202f8f0] dev_xdp_install at ffffffffa89fbbcc  8 [ffff9fe16202f920] dev_change_xdp_fd at ffffffffa8a08808  9 [ffff9fe16202f960] do_setlink at ffffffffa8a20235 10 [ffff9fe16202fa88] rtnl_setlink at ffffffffa8a20384 11 [ffff9fe16202fc78] rtnetlink_rcv_msg at ffffffffa8a1a8dd 12 [ffff9fe16202fcf0] netlink_rcv_skb at ffffffffa8a717eb 13 [ffff9fe16202fd40] netlink_unicast at ffffffffa8a70f88 14 [ffff9fe16202fd80] netlink_sendmsg at ffffffffa8a71319 15 [ffff9fe16202fdf0] sock_sendmsg at ffffffffa89df290 16 [ffff9fe16202fe08] __sys_sendto at ffffffffa89e19c8 17 [ffff9fe16202ff30] __x64_sys_sendto at ffffffffa89e1a64 18 [ffff9fe16202ff38] do_syscall_64 at ffffffffa84042b9 19 [ffff9fe16202ff50] entry_SYSCALL_64_after_hwframe at ffffffffa8c0008c  So I fix ixgbe_max_channels so that it will not allow a setting of queues to be higher than the num_online_cpus(). And when run to ixgbe_xdp_setup, take the smaller value of num_rx_queues and num_xdp_queues.","modified":"2026-09-15T09:02:35.673019315Z","published":"2024-05-21T15:15:25.360Z","upstream":["CVE-2021-47399"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2021-47399"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47399.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47399.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2021-47399.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}