CVE-2021-47023: net: marvell: prestera: fix port event handling on init

Published Feb 28, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: marvell: prestera: fix port event handling on init

For some reason there might be a crash during ports creation if port events are handling at the same time because fw may send initial port event with down state.

The crash points to canceldelayedwork() which is called when port went is down. Currently I did not find out the real cause of the issue, so fixed it by cancel port stats work only if previous port's state was up & runnig.

The following is the crash which can be triggered:

[ 28.311104] Unable to handle kernel paging request at virtual address 000071775f776600 [ 28.319097] Mem abort info: [ 28.321914] ESR = 0x96000004 [ 28.324996] EC = 0x25: DABT (current EL), IL = 32 bits [ 28.330350] SET = 0, FnV = 0 [ 28.333430] EA = 0, S1PTW = 0 [ 28.336597] Data abort info: [ 28.339499] ISV = 0, ISS = 0x00000004 [ 28.343362] CM = 0, WnR = 0 [ 28.346354] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000100bf7000 [ 28.352842] [000071775f776600] pgd=0000000000000000, p4d=0000000000000000 [ 28.359695] Internal error: Oops: 96000004 [#1] PREEMPT SMP [ 28.365310] Modules linked in: presterapci(+) prestera uiopdrvgenirq [ 28.372005] CPU: 0 PID: 1291 Comm: kworker/0:1H Not tainted 5.11.0-rc4 #1 [ 28.378846] Hardware name: DNI AmazonGo1 A7040 board (DT) [ 28.384283] Workqueue: presterafwwq presterafwevtworkfn [presterapci] [ 28.391413] pstate: 60000085 (nZCv daIf -PAN -UAO -TCO BTYPE=--) [ 28.397468] pc : getworkpool+0x48/0x60 [ 28.401442] lr : trytograbpending+0x6c/0x1b0 [ 28.406018] sp : ffff80001391bc60 [ 28.409358] x29: ffff80001391bc60 x28: 0000000000000000 [ 28.414725] x27: ffff000104fc8b40 x26: ffff80001127de88 [ 28.420089] x25: 0000000000000000 x24: ffff000106119760 [ 28.425452] x23: ffff00010775dd60 x22: ffff00010567e000 [ 28.430814] x21: 0000000000000000 x20: ffff80001391bcb0 [ 28.436175] x19: ffff00010775deb8 x18: 00000000000000c0 [ 28.441537] x17: 0000000000000000 x16: 000000008d9b0e88 [ 28.446898] x15: 0000000000000001 x14: 00000000000002ba [ 28.452261] x13: 80a3002c00000002 x12: 00000000000005f4 [ 28.457622] x11: 0000000000000030 x10: 000000000000000c [ 28.462985] x9 : 000000000000000c x8 : 0000000000000030 [ 28.468346] x7 : ffff800014400000 x6 : ffff000106119758 [ 28.473708] x5 : 0000000000000003 x4 : ffff00010775dc60 [ 28.479068] x3 : 0000000000000000 x2 : 0000000000000060 [ 28.484429] x1 : 000071775f776600 x0 : ffff00010775deb8 [ 28.489791] Call trace: [ 28.492259] getworkpool+0x48/0x60 [ 28.495874] canceldelayedwork+0x38/0xb0 [ 28.500011] presteraporthandleevent+0x90/0xa0 [prestera] [ 28.505743] presteraevtrecv+0x98/0xe0 [prestera] [ 28.510683] presterafwevtworkfn+0x180/0x228 [presterapci] [ 28.516660] processonework+0x1e8/0x360 [ 28.520710] workerthread+0x44/0x480 [ 28.524412] kthread+0x154/0x160 [ 28.527670] retfromfork+0x10/0x38 [ 28.531290] Code: a8c17bfd d50323bf d65f03c0 9278dc21 (f9400020) [ 28.537429] ---[ end trace 5eced933df3a080b ]---

Affected Software

5 affected components
Linux Kernel
Marvell Prestera
Linux Linux kernel>=5.10<5.10.37
Linux Linux kernel>=5.11<5.11.21
Linux Linux kernel>=5.12<5.12.4

Event History

Feb 28, 2024
CVE Published
via MITRE·08:13 AM
Data Sourced
via MITRE·08:13 AM
Description
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2021-47023?

CVE-2021-47023 is classified with a medium severity level due to the potential for crashes during port creation.

2

How do I fix CVE-2021-47023?

To fix CVE-2021-47023, update your Linux kernel or Marvell Prestera software to the latest version where the vulnerability has been addressed.

3

What causes the CVE-2021-47023 vulnerability?

CVE-2021-47023 is caused by improper handling of port events during their initialization, leading to potential crashes.

4

Which software is affected by CVE-2021-47023?

CVE-2021-47023 affects the Linux kernel and Marvell Prestera devices that utilize the impacted networking functionalities.

5

Is CVE-2021-47023 exploitable remotely?

CVE-2021-47023 is not considered remotely exploitable but may cause issues in local environments during port initialization.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203