<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T17:53:08.894591+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2023-52854</id>
    <title>CVE-2023-52854 — padata: Fix refcnt handling in padata_free_shell()</title>
    <updated>2026-10-08T17:53:08.895938+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>padata: Fix refcnt handling in padata_free_shell()</p>
<p>In a high-load arm64 environment, the pcrypt_aead01 test in LTP can lead
to system UAF (Use-After-Free) issues. Due to the lengthy analysis of
the pcrypt_aead01 function call, I'll describe the problem scenario
using a simplified model:</p>
<p>Suppose there's a user of padata named `user_function` that adheres to
the padata requirement of calling `padata_free_shell` after `serial()`
has been invoked, as demonstrated in the following code:</p>
<p>```c
struct request {
    struct padata_priv padata;
    struct completion *done;
};</p>
<p>void parallel(struct padata_priv *padata) {
    do_something();
}</p>
<p>void serial(struct padata_priv *padata) {
    struct request *request = container_of(padata,
    				struct request,
				padata);
    complete(request-&gt;done);
}</p>
<p>void user_function() {
    DECLARE_COMPLETION(done)
    padata-&gt;parallel = parallel;
    padata-&gt;serial = serial;
    padata_do_parallel();
    wait_for_completion(&amp;done);
    padata_free_shell();
}
```</p>
<p>In the corresponding padata.c file, there's the following code:</p>
<p>```c
static void padata_serial_worker(struct work_struct *serial_work) {
    ...
    cnt = 0;</p>
<p>while (!list_empty(&amp;local_list)) {
        ...
        padata-&gt;serial(padata);
        cnt++;
    }</p>
<p>local_bh_enable();</p>
<p>if (refcount_sub_and_test(cnt, &amp;pd-&gt;refcnt))
        padata_free_pd(pd);
}
```</p>
<p>Because of the high system load and the accumula…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2023-52854"/>
  </entry>
</feed>
