{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2021-47374","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-21T14:58:30.811Z","datePublished":"2024-05-21T15:03:38.436Z","dateUpdated":"2026-08-05T08:47:30.228Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:47:30.228Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndma-debug: prevent an error message from causing runtime problems\n\nFor some drivers, that use the DMA API. This error message can be reached\nseveral millions of times per second, causing spam to the kernel's printk\nbuffer and bringing the CPU usage up to 100% (so, it should be rate\nlimited). However, since there is at least one driver that is in the\nmainline and suffers from the error condition, it is more useful to\nerr_printk() here instead of just rate limiting the error message (in hopes\nthat it will make it easier for other drivers that suffer from this issue\nto be spotted)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The vulnerable path is reached when a network NIC (notably fsl_dpaa2_eth) performs DMA mapping while processing packets; a remote peer sending traffic can drive millions of dma_map calls per second through this code.\nAC:L - Once CONFIG_DMA_API_DEBUG is enabled and a driver with overlapping mappings is present, the attacker reliably triggers the flood simply by generating high-rate network traffic with no race or special timing required.\nPR:N - No authentication or local account is required; unauthenticated remote packets that cause the NIC to map DMA buffers are sufficient to hit the unrate-limited pr_err path.\nUI:N - Exploitation requires no victim user action beyond the system already running with the affected driver receiving or transmitting network traffic.\nS:U - The DoS affects only the local kernel/system availability and does not cross a security boundary such as a VM, IOMMU, or sandbox escape.\nC:N - The bug only floods an error string via pr_err; it does not read, leak, or expose kernel or user memory contents.\nI:N - There is no memory corruption, write primitive, or control-flow hijack in this defect—only excessive logging—so integrity is unaffected.\nA:H - The unrate-limited error can fire millions of times per second, saturating the printk buffer and driving CPU to 100%, fully denying service as documented in the original report."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/dma/debug.c"],"versions":[{"version":"2b4bbc6231d789f58676d2ccc42177df163e1c4a","lessThan":"de4afec2d2946c92c62a15ab341c70b287289e6a","status":"affected","versionType":"git"},{"version":"2b4bbc6231d789f58676d2ccc42177df163e1c4a","lessThan":"510e1a724ab1bf38150be2c1acabb303f98d0047","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/dma/debug.c"],"versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","status":"unaffected","versionType":"semver"},{"version":"5.14.9","lessThanOrEqual":"5.14.*","status":"unaffected","versionType":"semver"},{"version":"5.15","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"5.14.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.14","versionEndExcluding":"5.15"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/de4afec2d2946c92c62a15ab341c70b287289e6a"},{"url":"https://git.kernel.org/stable/c/510e1a724ab1bf38150be2c1acabb303f98d0047"}],"title":"dma-debug: prevent an error message from causing runtime problems","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T05:32:08.654Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/de4afec2d2946c92c62a15ab341c70b287289e6a","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/510e1a724ab1bf38150be2c1acabb303f98d0047","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2021-47374","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-09-10T15:38:22.986319Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-11T17:33:56.494Z"}}]}}