LiveActive security incident?Get immediate response
CVE Record

CVE-2021-46938: dm rq: fix double free of blk_mq_tag_set in dev remove after table load fails

In the Linux kernel, the following vulnerability has been resolved: dm rq: fix double free of blk_mq_tag_set in dev remove after table load fails When loading a device-mapper table for a request-based mapped device, and the allocation/initialization of the blk_mq_tag_set for the device fails, a following device remove will cause a double free. E.g. (dmesg): device-mapper: core: Cannot initialize queue for request-based dm-mq mapped device device-mapper: ioctl: unable to set up device queue for new table. Unable to handle kernel pointer dereference in virtual kernel address space Failing address: 0305e098835de000 TEID: 0305e098835de803 Fault in home space mode while using kernel ASCE. AS:000000025efe0007 R3:0000000000000024 Oops: 0038 ilc:3 [#1] SMP Modules linked in: ... lots of modules ... Supported: Yes, External CPU: 0 PID: 7348 Comm: multipathd Kdump: loaded Tainted: G W X 5.3.18-53-default #1 SLE15-SP3 Hardware name: IBM 8561 T01 7I2 (LPAR) Krnl PSW : 0704e00180000000 000000025e368eca (kfree+0x42/0x330) R:0 T:1 IO:1 EX:1 Key:0 M:1 W:0 P:0 AS:3 CC:2 PM:0 RI:0 EA:3 Krnl GPRS: 000000000000004a 000000025efe5230 c1773200d779968d 0000000000000000 000000025e520270 000000025e8d1b40 0000000000000003 00000007aae10000 000000025e5202a2 0000000000000001 c1773200d779968d 0305e098835de640 00000007a8170000 000003ff80138650 000000025e5202a2 000003e00396faa8 Krnl Code: 000000025e368eb8: c4180041e100 lgrl %r1,25eba50b8 000000025e368ebe: ecba06b93a55 risbg %r11,%r10,6,185,58 #000000025e368ec4: e3b010000008 ag %r11,0(%r1) >000000025e368eca: e310b0080004 lg %r1,8(%r11) 000000025e368ed0: a7110001 tmll %r1,1 000000025e368ed4: a7740129 brc 7,25e369126 000000025e368ed8: e320b0080004 lg %r2,8(%r11) 000000025e368ede: b904001b lgr %r1,%r11 Call Trace: [<000000025e368eca>] kfree+0x42/0x330 [<000000025e5202a2>] blk_mq_free_tag_set+0x72/0xb8 [<000003ff801316a8>] dm_mq_cleanup_mapped_device+0x38/0x50 [dm_mod] [<000003ff80120082>] free_dev+0x52/0xd0 [dm_mod] [<000003ff801233f0>] __dm_destroy+0x150/0x1d0 [dm_mod] [<000003ff8012bb9a>] dev_remove+0x162/0x1c0 [dm_mod] [<000003ff8012a988>] ctl_ioctl+0x198/0x478 [dm_mod] [<000003ff8012ac8a>] dm_ctl_ioctl+0x22/0x38 [dm_mod] [<000000025e3b11ee>] ksys_ioctl+0xbe/0xe0 [<000000025e3b127a>] __s390x_sys_ioctl+0x2a/0x40 [<000000025e8c15ac>] system_call+0xd8/0x2c8 Last Breaking-Event-Address: [<000000025e52029c>] blk_mq_free_tag_set+0x6c/0xb8 Kernel panic - not syncing: Fatal exception: panic_on_oops When allocation/initialization of the blk_mq_tag_set fails in dm_mq_init_request_queue(), it is uninitialized/freed, but the pointer is not reset to NULL; so when dev_remove() later gets into dm_mq_cleanup_mapped_device() it sees the pointer and tries to uninitialize and free it again. Fix this by setting the pointer to NULL in dm_mq_init_request_queue() error-handling. Also set it to NULL in dm_mq_cleanup_mapped_device().

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

A Linux kernel device-mapper cleanup bug can double-free memory after a request-based mapped device table fails to load. The observed failure path can end in a kernel oops and panic, creating availability risk on affected systems. The source bundle does not show active exploitation or a CVSS score.

Executive priority

Patch during normal high-priority kernel maintenance, escalating for storage-heavy or multipath-dependent systems. There is credible crash impact, but the provided evidence does not support emergency treatment for internet-facing exploitation.

Technical view

The bug is in request-based device-mapper queue setup. If blk_mq_tag_set allocation or initialization fails, the pointer was freed but not cleared. Later device removal could treat the stale pointer as valid and free it again. Kernel stable commits clear the pointer in error handling and cleanup paths.

Likely exposure

Exposure is most likely on Linux systems using request-based device-mapper configurations, such as multipath-related environments, with affected kernel versions before the relevant stable fixes. Systems not using this path are less likely exposed, but kernel provenance should be verified.

Exploitation context

The source describes a crash sequence from a table-load failure followed by device removal. CISA KEV status is false in the bundle, and no provided source claims in-the-wild exploitation. Treat this primarily as a stability and denial-of-service concern unless vendor advisories say otherwise.

Researcher notes

The vulnerable condition is an error path after dm_mq_init_request_queue failure, followed by dev_remove cleanup. The fix clears md->tag_set after failed initialization and during dm_mq_cleanup_mapped_device. Evidence is incomplete on attacker prerequisites, reachability, and distribution-specific exposure.

Mitigation direction

  • Update affected Linux kernels to vendor builds containing the referenced stable fixes.
  • Prioritize hosts using device-mapper, multipath, or request-based mapped devices.
  • Check Linux distribution advisories for exact fixed package versions.
  • Avoid direct wrangler or deployment assumptions; use standard OS patch channels.
  • Plan maintenance for storage infrastructure where kernel restarts may be required.

Validation and detection

  • Inventory kernel versions across Linux hosts and appliances.
  • Identify systems using device-mapper or multipath services.
  • Compare running kernels with vendor advisories and referenced stable commits.
  • Review kernel logs for device-mapper queue initialization failures or oops traces.
  • Confirm patched hosts rebooted into the fixed kernel.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-46938 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
9Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux1c357a1e86a4227a6b6059f2de118ae47659cebc, 1c357a1e86a4227a6b6059f2de118ae47659cebc, 1c357a1e86a4227a6b6059f2de118ae47659cebc, 1c357a1e86a4227a6b6059f2de118ae47659cebc, 1c357a1e86a4227a6b6059f2de118ae47659cebc, 1c357a1e86a4227a6b6059f2de118ae47659cebc, 1c357a1e86a4227a6b6059f2de118ae47659cebc, 1c357a1e86a4227a6b6059f2de118ae47659cebcunaffected
LinuxLinux4.6, 0, 4.9.269, 4.14.233, 4.19.191, 5.4.118, 5.10.36, 5.11.20, 5.12.3, 5.13affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.