<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 23:22:17 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-49465 — blk-throttle: Set BIO_THROTTLED when bio has been throttled</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-49465</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;blk-throttle: Set BIO_THROTTLED when bio has been throttled&lt;/p&gt;
&lt;p&gt;1.In current process, all bio will set the BIO_THROTTLED flag
after __blk_throtl_bio().&lt;/p&gt;
&lt;p&gt;2.If bio needs to be throttled, it will start the timer and
stop submit bio directly. Bio will submit in
blk_throtl_dispatch_work_fn() when the timer expires.But in
the current process, if bio is throttled. The BIO_THROTTLED
will be set to bio after timer start. If the bio has been
completed, it may cause use-after-free blow.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: use-after-free in blk_throtl_bio+0x12f0/0x2c70
Read of size 2 at addr ffff88801b8902d4 by task fio/26380&lt;/p&gt;
&lt;p&gt;dump_stack+0x9b/0xce
 print_address_description.constprop.6+0x3e/0x60
 kasan_report.cold.9+0x22/0x3a
 blk_throtl_bio+0x12f0/0x2c70
 submit_bio_checks+0x701/0x1550
 submit_bio_noacct+0x83/0xc80
 submit_bio+0xa7/0x330
 mpage_readahead+0x380/0x500
 read_pages+0x1c1/0xbf0
 page_cache_ra_unbounded+0x471/0x6f0
 do_page_cache_ra+0xda/0x110
 ondemand_readahead+0x442/0xae0
 page_cache_async_ra+0x210/0x300
 generic_file_buffered_read+0x4d9/0x2130
 generic_file_read_iter+0x315/0x490
 blkdev_read_iter+0x113/0x1b0
 aio_read+0x2ad/0x450
 io_submit_one+0xc8e/0x1d60
 __se_sys_io_submit+0x125/0x350
 do_syscall_64+0x2d/0x40
 entry_SYSCALL_64_after_hwframe+0x44/0xa9&lt;/p&gt;
&lt;p&gt;Allocated by task 26380:
 kasan_save_stack+0x19/0x40
 __kasan_kmalloc.constprop.2+0xc1/0xd0
 kmem_cache_alloc+0x146/0x440
 mempool_alloc+0x125/0x2f0
 bio_alloc_bioset+0x353/0x…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;blk-throttle: Set BIO_THROTTLED when bio has been throttled&lt;/p&gt;
&lt;p&gt;1.In current process, all bio will set the BIO_THROTTLED flag
after __blk_throtl_bio().&lt;/p&gt;
&lt;p&gt;2.If bio needs to be throttled, it will start the timer and
stop submit bio directly. Bio will submit in
blk_throtl_dispatch_work_fn() when the timer expires.But in
the current process, if bio is throttled. The BIO_THROTTLED
will be set to bio after timer start. If the bio has been
completed, it may cause use-after-free blow.&lt;/p&gt;
&lt;p&gt;BUG: KASAN: use-after-free in blk_throtl_bio+0x12f0/0x2c70
Read of size 2 at addr ffff88801b8902d4 by task fio/26380&lt;/p&gt;
&lt;p&gt;dump_stack+0x9b/0xce
 print_address_description.constprop.6+0x3e/0x60
 kasan_report.cold.9+0x22/0x3a
 blk_throtl_bio+0x12f0/0x2c70
 submit_bio_checks+0x701/0x1550
 submit_bio_noacct+0x83/0xc80
 submit_bio+0xa7/0x330
 mpage_readahead+0x380/0x500
 read_pages+0x1c1/0xbf0
 page_cache_ra_unbounded+0x471/0x6f0
 do_page_cache_ra+0xda/0x110
 ondemand_readahead+0x442/0xae0
 page_cache_async_ra+0x210/0x300
 generic_file_buffered_read+0x4d9/0x2130
 generic_file_read_iter+0x315/0x490
 blkdev_read_iter+0x113/0x1b0
 aio_read+0x2ad/0x450
 io_submit_one+0xc8e/0x1d60
 __se_sys_io_submit+0x125/0x350
 do_syscall_64+0x2d/0x40
 entry_SYSCALL_64_after_hwframe+0x44/0xa9&lt;/p&gt;
&lt;p&gt;Allocated by task 26380:
 kasan_save_stack+0x19/0x40
 __kasan_kmalloc.constprop.2+0xc1/0xd0
 kmem_cache_alloc+0x146/0x440
 mempool_alloc+0x125/0x2f0
 bio_alloc_bioset+0x353/0x…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-49465</guid>
    </item>
    <item>
      <title>USN-8096-1 — linux, linux-aws, linux-gcp, linux-gkeop, linux-ibm, linux-ibm-5.15, linux-intel-iotg, linux-kvm, linux-lowlatency, lin…</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8096-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: linux-ibm-5.15, Ubuntu:Pro:20.04:LTS: linux-nvidia-tegra-5.15, Ubuntu:22.04:LTS: linux, Ubuntu:22.04:LTS: linux-aws, Ubuntu:22.04:LTS: linux-gcp, Ubuntu:22.04:LTS: linux-gkeop, Ubuntu:22.04:LTS: linux-ibm, Ubuntu:22.04:LTS: linux-intel-iotg, Ubuntu:22.04:LTS: linux-kvm, Ubuntu:22.04:LTS: linux-lowlatency and 4 more&lt;/p&gt;
&lt;p&gt;Qualys discovered that several vulnerabilities existed in the AppArmor
Linux kernel Security Module (LSM). An unprivileged local attacker could
use these issues to load, replace, and remove arbitrary AppArmor profiles
causing denial of service, exposure of sensitive information (kernel
memory), local privilege escalation, or possibly escape a container.
(LP: #2143853)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - PowerPC architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - ACPI drivers;
  - ATM drivers;
  - Drivers core;
  - Network block device driver;
  - Bluetooth drivers;
  - Character device driver;
  - TPM device driver;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - Intel Stratix 10 firmware drivers;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - Input Device (Tablet) drivers;
  - ISDN/mISDN subsystem;
  - Macintosh device drivers;
  - Media drivers;
  - MOST (Media Oriented Systems Transport) drivers;
  - MTD block device drivers;
  - Network drivers;
  - Mellanox network drivers;
  - Texas Instruments network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - NVME drivers;
  - PA-RISC drivers;
  - PCI subsyste…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: linux-ibm-5.15, Ubuntu:Pro:20.04:LTS: linux-nvidia-tegra-5.15, Ubuntu:22.04:LTS: linux, Ubuntu:22.04:LTS: linux-aws, Ubuntu:22.04:LTS: linux-gcp, Ubuntu:22.04:LTS: linux-gkeop, Ubuntu:22.04:LTS: linux-ibm, Ubuntu:22.04:LTS: linux-intel-iotg, Ubuntu:22.04:LTS: linux-kvm, Ubuntu:22.04:LTS: linux-lowlatency and 4 more&lt;/p&gt;
&lt;p&gt;Qualys discovered that several vulnerabilities existed in the AppArmor
Linux kernel Security Module (LSM). An unprivileged local attacker could
use these issues to load, replace, and remove arbitrary AppArmor profiles
causing denial of service, exposure of sensitive information (kernel
memory), local privilege escalation, or possibly escape a container.
(LP: #2143853)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - PowerPC architecture;
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - ACPI drivers;
  - ATM drivers;
  - Drivers core;
  - Network block device driver;
  - Bluetooth drivers;
  - Character device driver;
  - TPM device driver;
  - Data acquisition framework and drivers;
  - Counter interface drivers;
  - CPU frequency scaling framework;
  - Intel Stratix 10 firmware drivers;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - IIO subsystem;
  - InfiniBand drivers;
  - Input Device core drivers;
  - Input Device (Tablet) drivers;
  - ISDN/mISDN subsystem;
  - Macintosh device drivers;
  - Media drivers;
  - MOST (Media Oriented Systems Transport) drivers;
  - MTD block device drivers;
  - Network drivers;
  - Mellanox network drivers;
  - Texas Instruments network drivers;
  - Ethernet team driver;
  - MediaTek network drivers;
  - NVME drivers;
  - PA-RISC drivers;
  - PCI subsyste…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8096-1</guid>
    </item>
  </channel>
</rss>
