<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 15:18:06 +0000</lastBuildDate>
    <item>
      <title>CVE-2023-52854 — padata: Fix refcnt handling in padata_free_shell()</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-52854</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;padata: Fix refcnt handling in padata_free_shell()&lt;/p&gt;
&lt;p&gt;In a high-load arm64 environment, the pcrypt_aead01 test in LTP can lead
to system UAF (Use-After-Free) issues. Due to the lengthy analysis of
the pcrypt_aead01 function call, I&amp;#39;ll describe the problem scenario
using a simplified model:&lt;/p&gt;
&lt;p&gt;Suppose there&amp;#39;s a user of padata named `user_function` that adheres to
the padata requirement of calling `padata_free_shell` after `serial()`
has been invoked, as demonstrated in the following code:&lt;/p&gt;
&lt;p&gt;```c
struct request {
    struct padata_priv padata;
    struct completion *done;
};&lt;/p&gt;
&lt;p&gt;void parallel(struct padata_priv *padata) {
    do_something();
}&lt;/p&gt;
&lt;p&gt;void serial(struct padata_priv *padata) {
    struct request *request = container_of(padata,
    				struct request,
				padata);
    complete(request-&amp;gt;done);
}&lt;/p&gt;
&lt;p&gt;void user_function() {
    DECLARE_COMPLETION(done)
    padata-&amp;gt;parallel = parallel;
    padata-&amp;gt;serial = serial;
    padata_do_parallel();
    wait_for_completion(&amp;amp;done);
    padata_free_shell();
}
```&lt;/p&gt;
&lt;p&gt;In the corresponding padata.c file, there&amp;#39;s the following code:&lt;/p&gt;
&lt;p&gt;```c
static void padata_serial_worker(struct work_struct *serial_work) {
    ...
    cnt = 0;&lt;/p&gt;
&lt;p&gt;while (!list_empty(&amp;amp;local_list)) {
        ...
        padata-&amp;gt;serial(padata);
        cnt++;
    }&lt;/p&gt;
&lt;p&gt;local_bh_enable();&lt;/p&gt;
&lt;p&gt;if (refcount_sub_and_test(cnt, &amp;amp;pd-&amp;gt;refcnt))
        padata_free_pd(pd);
}
```&lt;/p&gt;
&lt;p&gt;Because of the high system load and the accumula…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;padata: Fix refcnt handling in padata_free_shell()&lt;/p&gt;
&lt;p&gt;In a high-load arm64 environment, the pcrypt_aead01 test in LTP can lead
to system UAF (Use-After-Free) issues. Due to the lengthy analysis of
the pcrypt_aead01 function call, I&amp;#39;ll describe the problem scenario
using a simplified model:&lt;/p&gt;
&lt;p&gt;Suppose there&amp;#39;s a user of padata named `user_function` that adheres to
the padata requirement of calling `padata_free_shell` after `serial()`
has been invoked, as demonstrated in the following code:&lt;/p&gt;
&lt;p&gt;```c
struct request {
    struct padata_priv padata;
    struct completion *done;
};&lt;/p&gt;
&lt;p&gt;void parallel(struct padata_priv *padata) {
    do_something();
}&lt;/p&gt;
&lt;p&gt;void serial(struct padata_priv *padata) {
    struct request *request = container_of(padata,
    				struct request,
				padata);
    complete(request-&amp;gt;done);
}&lt;/p&gt;
&lt;p&gt;void user_function() {
    DECLARE_COMPLETION(done)
    padata-&amp;gt;parallel = parallel;
    padata-&amp;gt;serial = serial;
    padata_do_parallel();
    wait_for_completion(&amp;amp;done);
    padata_free_shell();
}
```&lt;/p&gt;
&lt;p&gt;In the corresponding padata.c file, there&amp;#39;s the following code:&lt;/p&gt;
&lt;p&gt;```c
static void padata_serial_worker(struct work_struct *serial_work) {
    ...
    cnt = 0;&lt;/p&gt;
&lt;p&gt;while (!list_empty(&amp;amp;local_list)) {
        ...
        padata-&amp;gt;serial(padata);
        cnt++;
    }&lt;/p&gt;
&lt;p&gt;local_bh_enable();&lt;/p&gt;
&lt;p&gt;if (refcount_sub_and_test(cnt, &amp;amp;pd-&amp;gt;refcnt))
        padata_free_pd(pd);
}
```&lt;/p&gt;
&lt;p&gt;Because of the high system load and the accumula…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-52854</guid>
    </item>
  </channel>
</rss>
