{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2021-47551","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-24T15:02:54.832Z","datePublished":"2024-05-24T15:09:54.635Z","dateUpdated":"2026-08-05T08:48:20.962Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T08:48:20.962Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/amdkfd: Fix kernel panic when reset failed and been triggered again\n\nIn SRIOV configuration, the reset may failed to bring asic back to normal but stop cpsch\nalready been called, the start_cpsch will not be called since there is no resume in this\ncase.  When reset been triggered again, driver should avoid to do uninitialization again."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable stop_cpsch path is reached during GPU reset of an AMD KFD device (via /dev/kfd or DRM render-node workloads that hang the GPU), requiring local access to the compute/graphics device nodes rather than network packet processing.\nAC:L - An attacker who can submit GPU work can induce an HWS hang that schedules reset; in SRIOV, amdgpu_device_reset_sriov retries after failure and re-enters stop_cpsch without start_cpsch, so the double-uninit is reliably hit once a reset fails or is retried.\nPR:L - Triggering requires only unprivileged access to /dev/kfd or a DRM render node (typically render-group membership), not real root or init-namespace capabilities.\nUI:N - The attacker triggers GPU hang and subsequent reset through their own device ioctls; no separate victim action is required.\nS:U - The double-free and panic occur in the same kernel that hosts the amdkfd driver (including a guest with an SRIOV VF); this does not cross a VM/IOMMU security boundary into the host.\nC:H - stop_cpsch frees dqm->fence_mem without NULLing it, so a second call is a use-after-free of the kfd_mem_obj; per UAF guidance this can be leveraged for arbitrary kernel read/disclosure primitives.\nI:H - The same dangling fence_mem leads to a double kfree and GTT SA bitmap corruption, and pm_uninit is invoked twice on a torn-down packet manager—memory corruption consistent with write/control-flow hijack primitives.\nA:H - The second stop_cpsch causes kernel panic/oops via UAF/double-free and NULL dereference in kernel_queue_uninit(pm->priv_queue) after priv_queue was already set to NULL."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c"],"versions":[{"version":"2c99a547bcf9bb8532abd2953479949018449f93","lessThan":"74aafe99efb68f15e50be9f7032c2168512f98a8","status":"affected","versionType":"git"},{"version":"2c99a547bcf9bb8532abd2953479949018449f93","lessThan":"06c6f8f86ec243b89e52f0c3dc7062bcb9de74df","status":"affected","versionType":"git"},{"version":"2c99a547bcf9bb8532abd2953479949018449f93","lessThan":"2cf49e00d40d5132e3d067b5aa6d84791929ab15","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c"],"versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","status":"unaffected","versionType":"semver"},{"version":"5.10.84","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.7","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"5.16","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"5.10.84"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"5.15.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"5.16"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/74aafe99efb68f15e50be9f7032c2168512f98a8"},{"url":"https://git.kernel.org/stable/c/06c6f8f86ec243b89e52f0c3dc7062bcb9de74df"},{"url":"https://git.kernel.org/stable/c/2cf49e00d40d5132e3d067b5aa6d84791929ab15"}],"title":"drm/amd/amdkfd: Fix kernel panic when reset failed and been triggered again","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-770","lang":"en","description":"CWE-770 Allocation of Resources Without Limits or Throttling"}]}],"affected":[{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"unaffected","lessThanOrEqual":"5.16","versionType":"custom"}]},{"vendor":"linux","product":"linux_kernel","cpes":["cpe:2.3:o:linux:linux_kernel:5.10.84:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"unaffected","lessThanOrEqual":"5.10.84","versionType":"custom"}]}],"metrics":[{"cvssV3_1":{"scope":"CHANGED","version":"3.1","baseScore":6.5,"attackVector":"LOCAL","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-05-28T15:41:59.377852Z","id":"CVE-2021-47551","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-05-22T13:29:22.031Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T05:39:59.853Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/74aafe99efb68f15e50be9f7032c2168512f98a8","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/06c6f8f86ec243b89e52f0c3dc7062bcb9de74df","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/2cf49e00d40d5132e3d067b5aa6d84791929ab15","tags":["x_transferred"]}]}]}}