<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 09:43:13 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-48954 — s390/qeth: fix use-after-free in hsci</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-48954</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;s390/qeth: fix use-after-free in hsci&lt;/p&gt;
&lt;p&gt;KASAN found that addr was dereferenced after br2dev_event_work was freed.&lt;/p&gt;
&lt;p&gt;==================================================================
BUG: KASAN: use-after-free in qeth_l2_br2dev_worker+0x5ba/0x6b0
Read of size 1 at addr 00000000fdcea440 by task kworker/u760:4/540
CPU: 17 PID: 540 Comm: kworker/u760:4 Tainted: G            E      6.1.0-20221128.rc7.git1.5aa3bed4ce83.300.fc36.s390x+kasan #1
Hardware name: IBM 8561 T01 703 (LPAR)
Workqueue: 0.0.8000_event qeth_l2_br2dev_worker
Call Trace:
 [&amp;lt;000000016944d4ce&amp;gt;] dump_stack_lvl+0xc6/0xf8
 [&amp;lt;000000016942cd9c&amp;gt;] print_address_description.constprop.0+0x34/0x2a0
 [&amp;lt;000000016942d118&amp;gt;] print_report+0x110/0x1f8
 [&amp;lt;0000000167a7bd04&amp;gt;] kasan_report+0xfc/0x128
 [&amp;lt;000000016938d79a&amp;gt;] qeth_l2_br2dev_worker+0x5ba/0x6b0
 [&amp;lt;00000001673edd1e&amp;gt;] process_one_work+0x76e/0x1128
 [&amp;lt;00000001673ee85c&amp;gt;] worker_thread+0x184/0x1098
 [&amp;lt;000000016740718a&amp;gt;] kthread+0x26a/0x310
 [&amp;lt;00000001672c606a&amp;gt;] __ret_from_fork+0x8a/0xe8
 [&amp;lt;00000001694711da&amp;gt;] ret_from_fork+0xa/0x40
Allocated by task 108338:
 kasan_save_stack+0x40/0x68
 kasan_set_track+0x36/0x48
 __kasan_kmalloc+0xa0/0xc0
 qeth_l2_switchdev_event+0x25a/0x738
 atomic_notifier_call_chain+0x9c/0xf8
 br_switchdev_fdb_notify+0xf4/0x110
 fdb_notify+0x122/0x180
 fdb_add_entry.constprop.0.isra.0+0x312/0x558
 br_fdb_add+0x59e/0x858
 rtnl_fdb_add+0x58a/0x928
 rtnetlink_rcv_msg+0x5f8/0x8d8
 netlink_rcv_skb+0…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;s390/qeth: fix use-after-free in hsci&lt;/p&gt;
&lt;p&gt;KASAN found that addr was dereferenced after br2dev_event_work was freed.&lt;/p&gt;
&lt;p&gt;==================================================================
BUG: KASAN: use-after-free in qeth_l2_br2dev_worker+0x5ba/0x6b0
Read of size 1 at addr 00000000fdcea440 by task kworker/u760:4/540
CPU: 17 PID: 540 Comm: kworker/u760:4 Tainted: G            E      6.1.0-20221128.rc7.git1.5aa3bed4ce83.300.fc36.s390x+kasan #1
Hardware name: IBM 8561 T01 703 (LPAR)
Workqueue: 0.0.8000_event qeth_l2_br2dev_worker
Call Trace:
 [&amp;lt;000000016944d4ce&amp;gt;] dump_stack_lvl+0xc6/0xf8
 [&amp;lt;000000016942cd9c&amp;gt;] print_address_description.constprop.0+0x34/0x2a0
 [&amp;lt;000000016942d118&amp;gt;] print_report+0x110/0x1f8
 [&amp;lt;0000000167a7bd04&amp;gt;] kasan_report+0xfc/0x128
 [&amp;lt;000000016938d79a&amp;gt;] qeth_l2_br2dev_worker+0x5ba/0x6b0
 [&amp;lt;00000001673edd1e&amp;gt;] process_one_work+0x76e/0x1128
 [&amp;lt;00000001673ee85c&amp;gt;] worker_thread+0x184/0x1098
 [&amp;lt;000000016740718a&amp;gt;] kthread+0x26a/0x310
 [&amp;lt;00000001672c606a&amp;gt;] __ret_from_fork+0x8a/0xe8
 [&amp;lt;00000001694711da&amp;gt;] ret_from_fork+0xa/0x40
Allocated by task 108338:
 kasan_save_stack+0x40/0x68
 kasan_set_track+0x36/0x48
 __kasan_kmalloc+0xa0/0xc0
 qeth_l2_switchdev_event+0x25a/0x738
 atomic_notifier_call_chain+0x9c/0xf8
 br_switchdev_fdb_notify+0xf4/0x110
 fdb_notify+0x122/0x180
 fdb_add_entry.constprop.0.isra.0+0x312/0x558
 br_fdb_add+0x59e/0x858
 rtnl_fdb_add+0x58a/0x928
 rtnetlink_rcv_msg+0x5f8/0x8d8
 netlink_rcv_skb+0…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-48954</guid>
    </item>
  </channel>
</rss>
