CVE-2021-47399: ixgbe: Fix NULL pointer dereference in ixgbe_xdp_setup
In the Linux kernel, the following vulnerability has been resolved:
ixgbe: Fix NULL pointer dereference in ixgbe_xdp_setup
The ixgbe driver currently generates a NULL pointer dereference with
some machine (online cpus < 63). This is due to the fact that the
maximum value of num_xdp_queues is nr_cpu_ids. Code is in
"ixgbe_set_rss_queues"".
Here's how the problem repeats itself:
Some machine (online cpus < 63), And user set num_queues to 63 through
ethtool. Code is in the "ixgbe_set_channels",
adapter->ring_feature[RING_F_FDIR].limit = count;
It becomes 63.
When user use xdp, "ixgbe_set_rss_queues" will set queues num.
adapter->num_rx_queues = rss_i;
adapter->num_tx_queues = rss_i;
adapter->num_xdp_queues = ixgbe_xdp_queues(adapter);
And rss_i's value is from
f = &adapter->ring_feature[RING_F_FDIR];
rss_i = f->indices = f->limit;
So "num_rx_queues" > "num_xdp_queues", when run to "ixgbe_xdp_setup",
for (i = 0; i < adapter->num_rx_queues; i++)
if (adapter->xdp_ring[i]->xsk_umem)
It leads to panic.
Call trace:
[exception RIP: ixgbe_xdp+368]
RIP: ffffffffc02a76a0 RSP: ffff9fe16202f8d0 RFLAGS: 00010297
RAX: 0000000000000000 RBX: 0000000000000020 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 000000000000001c RDI: ffffffffa94ead90
RBP: ffff92f8f24c0c18 R8: 0000000000000000 R9: 0000000000000000
R10: ffff9fe16202f830 R11: 0000000000000000 R12: ffff92f8f24c0000
R13: ffff9fe16202fc01 R14: 000000000000000a R15: ffffffffc02a7530
ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018
7 [ffff9fe16202f8f0] dev_xdp_install at ffffffffa89fbbcc
8 [ffff9fe16202f920] dev_change_xdp_fd at ffffffffa8a08808
9 [ffff9fe16202f960] do_setlink at ffffffffa8a20235
10 [ffff9fe16202fa88] rtnl_setlink at ffffffffa8a20384
11 [ffff9fe16202fc78] rtnetlink_rcv_msg at ffffffffa8a1a8dd
12 [ffff9fe16202fcf0] netlink_rcv_skb at ffffffffa8a717eb
13 [ffff9fe16202fd40] netlink_unicast at ffffffffa8a70f88
14 [ffff9fe16202fd80] netlink_sendmsg at ffffffffa8a71319
15 [ffff9fe16202fdf0] sock_sendmsg at ffffffffa89df290
16 [ffff9fe16202fe08] __sys_sendto at ffffffffa89e19c8
17 [ffff9fe16202ff30] __x64_sys_sendto at ffffffffa89e1a64
18 [ffff9fe16202ff38] do_syscall_64 at ffffffffa84042b9
19 [ffff9fe16202ff50] entry_SYSCALL_64_after_hwframe at ffffffffa8c0008c
So I fix ixgbe_max_channels so that it will not allow a setting of queues
to be higher than the num_online_cpus(). And when run to ixgbe_xdp_setup,
take the smaller value of num_rx_queues and num_xdp_queues.
Security readout for executives and security teams
Plain-English summary
CVE-2021-47399 is a Linux kernel bug in the ixgbe network driver. Under specific queue and XDP conditions, the driver can dereference a NULL pointer and panic the kernel. The business impact is primarily availability loss on affected Linux systems using this driver path.
Executive priority
Treat this as a targeted availability issue. Patch exposed ixgbe/XDP systems through normal kernel maintenance, faster for critical network infrastructure. It does not currently justify emergency response based on the provided exploitation evidence.
Technical view
The ixgbe XDP setup path can iterate over RX queues beyond allocated XDP queues after queue counts are set higher than online CPUs. Accessing adapter->xdp_ring[i]->xsk_umem can hit NULL and trigger a kernel panic. The source says fixes bound channel counts and use the smaller RX/XDP queue count.
Likely exposure
Exposure appears limited to Linux systems using the ixgbe driver, relevant kernel versions, and XDP or related queue configuration. The provided data lists Linux as affected and names version markers, but does not provide distribution-specific package status.
Exploitation context
No CISA KEV listing or cited source indicates active exploitation. The described trigger requires changing queue/channel configuration and then using XDP, so the evidence points to a configuration-triggered denial-of-service risk rather than remote code execution.
Researcher notes
The source describes a NULL pointer dereference in ixgbe_xdp_setup caused by num_rx_queues exceeding num_xdp_queues. Fixed commits adjust ixgbe_max_channels and bound iteration by the smaller queue count. Affected-version evidence is sparse and should be mapped through downstream kernel advisories.
Mitigation direction
Check vendor or distribution advisories for kernels containing the ixgbe fixes.
Prioritize patching Linux systems using ixgbe with XDP or custom queue settings.
Avoid unsupported queue counts on ixgbe systems until patched.
Do not test panic-triggering conditions on production systems.
Validation and detection
Inventory Linux hosts using the ixgbe driver.
Identify systems running XDP with ixgbe interfaces.
Compare installed kernel packages against vendor fixed versions.
Review change history for custom ethtool channel or queue settings.
Confirm no production systems rely on vulnerable kernel builds.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2021-47399 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.