LiveActive security incident?Get immediate response
CVE Record

CVE-2021-47081: habanalabs/gaudi: Fix a potential use after free in gaudi_memset_device_memory

In the Linux kernel, the following vulnerability has been resolved: habanalabs/gaudi: Fix a potential use after free in gaudi_memset_device_memory Our code analyzer reported a uaf. In gaudi_memset_device_memory, cb is get via hl_cb_kernel_create() with 2 refcount. If hl_cs_allocate_job() failed, the execution runs into release_cb branch. One ref of cb is dropped by hl_cb_put(cb) and could be freed if other thread also drops one ref. Then cb is used by cb->id later, which is a potential uaf. My patch add a variable 'id' to accept the value of cb->id before the hl_cb_put(cb) is called, to avoid the potential uaf.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2021-47081 is a Linux kernel driver bug in the Habana Labs Gaudi accelerator code. A failure path could use freed memory. The sources do not provide CVSS, confirmed exploitation, or broad impact details, so urgency depends mainly on whether your Linux systems use the Gaudi driver.

Executive priority

Treat this as targeted kernel maintenance, not an enterprise-wide emergency based on current evidence. Prioritize AI or accelerator hosts using Gaudi hardware, and rely on vendor advisories for final severity and patch timing.

Technical view

The issue is a potential use-after-free in gaudi_memset_device_memory. If hl_cs_allocate_job() fails, hl_cb_put(cb) may drop a reference and allow cb to be freed, while the code later reads cb->id. The stable fix stores cb->id before releasing the reference.

Likely exposure

Exposure appears limited to Linux systems running affected kernel versions with the habanalabs/gaudi driver or Habana Gaudi accelerator workloads. The bundle lists Linux 5.12 through 5.12.7 and 5.13-related version data, but exact downstream package exposure needs vendor confirmation.

Exploitation context

The source bundle says this was reported by code analysis and marks KEV as false. No cited source confirms active exploitation, public exploit availability, privilege impact, or remote reachability.

Researcher notes

The important code pattern is the failure path after hl_cs_allocate_job(). The fix avoids dereferencing cb after hl_cb_put(cb) by preserving the id first. Evidence is incomplete for exploitability, reachable attack surface, and severity scoring.

Mitigation direction

  • Check your Linux distribution or kernel vendor advisory for CVE-2021-47081 guidance.
  • Update affected kernels to a release containing the referenced stable kernel fixes.
  • Prioritize systems using Habana Labs Gaudi accelerators or habanalabs drivers.
  • If no vendor package is available, follow vendor guidance for supported kernel backports.

Validation and detection

  • Inventory Linux kernel versions on hosts using Gaudi accelerator hardware.
  • Confirm whether the habanalabs/gaudi driver is present and in use.
  • Verify the deployed kernel includes the referenced stable fix commits.
  • Track distribution-specific advisories because downstream version ranges may differ.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-47081 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
3Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux423815bf02e257091d5337be5c63b57fc29e4254, 423815bf02e257091d5337be5c63b57fc29e4254unaffected
LinuxLinux5.12, 0, 5.12.7, 5.13affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.