CVE-2021-47548·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port() The if statement: if (port >= DSAF_GE_NUM) return; limits the value of port less than DSAF_GE_NUM (i.e., 8). However, if the value of port is 6 or 7, an array overflow could occur: port_rst_off = dsaf_dev->mac_cb[port]->port_rst_off; because the length of dsaf_dev->mac_cb is DSAF_MAX_PORT_NUM (i.e., 6). To fix this possible array overflow, we first check port and if it is greater than or equal to DSAF_MAX_PORT_NUM, the function returns.
- Severity
- critical
- Software
- Kernel
- Fixed in
- 5.15.7
- Published
- 2024-05-24
Affected versions
From: 5.11
Until: 5.15.7
Fixed in: 5.15.7
How to fix this CVE
Update your Linux kernel to version 5.15.7 or later to address a critical array bounds checking vulnerability in the HiSilicon Ethernet driver. This flaw could allow local attackers to trigger memory corruption through improper port parameter validation. Kernel versions 5.11 through 5.15.6 are vulnerable and should be patched immediately.
sudo dnf update kernel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Check installed kernel version: uname -r | grep -E '^5\.(1[1-4]|15\.[0-6])'
- Verify if HiSilicon Ethernet driver is loaded: lsmod | grep -i hns
- Monitor kernel logs for memory access violations: journalctl -xe | grep -i 'BUG\|OOPS\|segfault'
- Confirm kernel patch after update: uname -r should show version 5.15.7 or higher
FAQ
What is CVE-2021-47548?
This critical vulnerability exists in the HiSilicon Ethernet driver where the port validation check allows indices 6 and 7 to pass through, but the underlying array only supports indices 0-5, leading to out-of-bounds memory access and potential system compromise.
Is CVE-2021-47548 being actively exploited?
No, this vulnerability is not listed in the CISA KEV catalog and has no known public exploits available. However, its critical CVSS score (9.8) warrants immediate patching as proof-of-concept code could emerge.
What versions of Kernel are affected by CVE-2021-47548?
Linux kernel versions 5.11 through 5.15.6 are vulnerable. Version 5.15.7 and all subsequent releases contain the fix.
How do I check if my server is vulnerable to CVE-2021-47548?
Run 'uname -r' and compare the output against the vulnerable range (5.11-5.15.6). If lsmod shows the hns driver is loaded, the system is vulnerable unless kernel version is 5.15.7 or newer.
Does Defensia detect CVE-2021-47548?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2021-47548 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/22519eff7df2d88adcc2568d86046ce1e2b52803
- https://git.kernel.org/stable/c/948968f8747650447c8f21c9fdba0e1973be040b
- https://git.kernel.org/stable/c/99bb25cb6753beaf2c2bc37927c2ecc0ceff3f6d
- https://git.kernel.org/stable/c/a66998e0fbf213d47d02813b9679426129d0d114
- https://git.kernel.org/stable/c/abbd5faa0748d0aa95d5191d56ff7a17a6275bd1
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2021-47548. Free for 1 server.
Get started free