<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:37:17 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-47399 — ixgbe: Fix NULL pointer dereference in ixgbe_xdp_setup</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-47399</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ixgbe: Fix NULL pointer dereference in ixgbe_xdp_setup&lt;/p&gt;
&lt;p&gt;The ixgbe driver currently generates a NULL pointer dereference with
some machine (online cpus &amp;lt; 63). This is due to the fact that the
maximum value of num_xdp_queues is nr_cpu_ids. Code is in
&amp;#34;ixgbe_set_rss_queues&amp;#34;&amp;#34;.&lt;/p&gt;
&lt;p&gt;Here&amp;#39;s how the problem repeats itself:
Some machine (online cpus &amp;lt; 63), And user set num_queues to 63 through
ethtool. Code is in the &amp;#34;ixgbe_set_channels&amp;#34;,
	adapter-&amp;gt;ring_feature[RING_F_FDIR].limit = count;&lt;/p&gt;
&lt;p&gt;It becomes 63.&lt;/p&gt;
&lt;p&gt;When user use xdp, &amp;#34;ixgbe_set_rss_queues&amp;#34; will set queues num.
	adapter-&amp;gt;num_rx_queues = rss_i;
	adapter-&amp;gt;num_tx_queues = rss_i;
	adapter-&amp;gt;num_xdp_queues = ixgbe_xdp_queues(adapter);&lt;/p&gt;
&lt;p&gt;And rss_i&amp;#39;s value is from
	f = &amp;amp;adapter-&amp;gt;ring_feature[RING_F_FDIR];
	rss_i = f-&amp;gt;indices = f-&amp;gt;limit;&lt;/p&gt;
&lt;p&gt;So &amp;#34;num_rx_queues&amp;#34; &amp;gt; &amp;#34;num_xdp_queues&amp;#34;, when run to &amp;#34;ixgbe_xdp_setup&amp;#34;,
	for (i = 0; i &amp;lt; adapter-&amp;gt;num_rx_queues; i++)
		if (adapter-&amp;gt;xdp_ring[i]-&amp;gt;xsk_umem)&lt;/p&gt;
&lt;p&gt;It leads to panic.&lt;/p&gt;
&lt;p&gt;Call trace:
[exception RIP: ixgbe_xdp+368]
RIP: ffffffffc02a76a0  RSP: ffff9fe16202f8d0  RFLAGS: 00010297
RAX: 0000000000000000  RBX: 0000000000000020  RCX: 0000000000000000
RDX: 0000000000000000  RSI: 000000000000001c  RDI: ffffffffa94ead90
RBP: ffff92f8f24c0c18   R8: 0000000000000000   R9: 0000000000000000
R10: ffff9fe16202f830  R11: 0000000000000000  R12: ffff92f8f24c0000
R13: ffff9fe16202fc01  R14: 000000000000000a  R15: ffffffffc02a7530
ORIG_RAX: fffffffffffffff…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;ixgbe: Fix NULL pointer dereference in ixgbe_xdp_setup&lt;/p&gt;
&lt;p&gt;The ixgbe driver currently generates a NULL pointer dereference with
some machine (online cpus &amp;lt; 63). This is due to the fact that the
maximum value of num_xdp_queues is nr_cpu_ids. Code is in
&amp;#34;ixgbe_set_rss_queues&amp;#34;&amp;#34;.&lt;/p&gt;
&lt;p&gt;Here&amp;#39;s how the problem repeats itself:
Some machine (online cpus &amp;lt; 63), And user set num_queues to 63 through
ethtool. Code is in the &amp;#34;ixgbe_set_channels&amp;#34;,
	adapter-&amp;gt;ring_feature[RING_F_FDIR].limit = count;&lt;/p&gt;
&lt;p&gt;It becomes 63.&lt;/p&gt;
&lt;p&gt;When user use xdp, &amp;#34;ixgbe_set_rss_queues&amp;#34; will set queues num.
	adapter-&amp;gt;num_rx_queues = rss_i;
	adapter-&amp;gt;num_tx_queues = rss_i;
	adapter-&amp;gt;num_xdp_queues = ixgbe_xdp_queues(adapter);&lt;/p&gt;
&lt;p&gt;And rss_i&amp;#39;s value is from
	f = &amp;amp;adapter-&amp;gt;ring_feature[RING_F_FDIR];
	rss_i = f-&amp;gt;indices = f-&amp;gt;limit;&lt;/p&gt;
&lt;p&gt;So &amp;#34;num_rx_queues&amp;#34; &amp;gt; &amp;#34;num_xdp_queues&amp;#34;, when run to &amp;#34;ixgbe_xdp_setup&amp;#34;,
	for (i = 0; i &amp;lt; adapter-&amp;gt;num_rx_queues; i++)
		if (adapter-&amp;gt;xdp_ring[i]-&amp;gt;xsk_umem)&lt;/p&gt;
&lt;p&gt;It leads to panic.&lt;/p&gt;
&lt;p&gt;Call trace:
[exception RIP: ixgbe_xdp+368]
RIP: ffffffffc02a76a0  RSP: ffff9fe16202f8d0  RFLAGS: 00010297
RAX: 0000000000000000  RBX: 0000000000000020  RCX: 0000000000000000
RDX: 0000000000000000  RSI: 000000000000001c  RDI: ffffffffa94ead90
RBP: ffff92f8f24c0c18   R8: 0000000000000000   R9: 0000000000000000
R10: ffff9fe16202f830  R11: 0000000000000000  R12: ffff92f8f24c0000
R13: ffff9fe16202fc01  R14: 000000000000000a  R15: ffffffffc02a7530
ORIG_RAX: fffffffffffffff…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-47399</guid>
    </item>
  </channel>
</rss>
