CVE-2021-46918: dmaengine: idxd: clear MSIX permission entry on shutdown
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: clear MSIX permission entry on shutdown
Add disabling/clearing of MSIX permission entries on device shutdown to
mirror the enabling of the MSIX entries on probe. Current code left the
MSIX enabled and the pasid entries still programmed at device shutdown.
Security readout for executives and security teams
Plain-English summary
This Linux kernel issue affects shutdown handling for the idxd DMA engine driver. The kernel failed to clear MSI-X permission and PASID programming when the device shut down. Business urgency depends on whether affected kernels and compatible idxd hardware are present. No source states active exploitation or a known public exploit.
Executive priority
Prioritize as a kernel hygiene and asset-scoping item, not an emergency, unless your fleet uses affected idxd-capable systems. The missing CVSS and exploit evidence mean urgency should be driven by exposure confirmation and normal kernel patch cycles.
Technical view
The vulnerability is in Linux kernel dmaengine idxd shutdown logic. The fix clears MSI-X permission entries on shutdown to mirror setup during probe, because prior code left MSI-X enabled and PASID entries programmed. The source bundle does not provide CVSS, CWE, attack prerequisites, or impact details beyond this driver state cleanup.
Likely exposure
Exposure appears limited to Linux systems running affected kernel versions with the idxd driver and relevant hardware support. The bundle references Linux 5.11 and 5.12-era affected data, but distribution backports may change practical exposure. Confirm against vendor kernel advisories.
Exploitation context
The CVE is not listed as KEV in the provided bundle, and no cited source states active exploitation. The available evidence describes a kernel shutdown-state bug, not a demonstrated attack path. Treat exploitability and impact as unconfirmed from these sources.
Researcher notes
The source bundle is sparse: it names the fixed behavior but omits impact analysis, CVSS, CWE, and attack conditions. Research should focus on mapping affected upstream commits to distro kernels and determining whether residual MSI-X/PASID state has a security-relevant consequence on deployed hardware.
Mitigation direction
Apply vendor kernel updates that include the referenced stable fixes.
Review Linux distribution advisories for CVE-2021-46918 backport status.
If patching is delayed, determine whether idxd hardware and driver support are used.
Follow vendor guidance for any temporary operational mitigations.
Avoid relying on upstream version numbers alone for distro kernels.
Validation and detection
Inventory Linux kernel versions across affected server and workstation fleets.
Check vendor changelogs for CVE-2021-46918 or the stable commit references.
Confirm whether the idxd driver is enabled or relevant hardware is present.
Prioritize validation on systems using advanced DMA acceleration features.
Document systems where distro backports already include the fix.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2021-46918 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.