<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 20:58:36 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-47706 — block, bfq: fix possible UAF for bfqq-&gt;bic with merge chain</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-47706</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens RUGGEDCOM RST2428P, Siemens SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, Siemens SCALANCE XCM-/XRM-/XCH-/XRH-300 family, Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;block, bfq: fix possible UAF for bfqq-&amp;gt;bic with merge chain&lt;/p&gt;
&lt;p&gt;1) initial state, three tasks:&lt;/p&gt;
&lt;p&gt;Process 1       Process 2	Process 3
		 (BIC1)          (BIC2)		 (BIC3)
		  |  Λ            |  Λ		  |  Λ
		  |  |            |  |		  |  |
		  V  |            V  |		  V  |
		  bfqq1           bfqq2		  bfqq3
process ref:	   1		    1		    1&lt;/p&gt;
&lt;p&gt;2) bfqq1 merged to bfqq2:&lt;/p&gt;
&lt;p&gt;Process 1       Process 2	Process 3
		 (BIC1)          (BIC2)		 (BIC3)
		  |               |		  |  Λ
		  \--------------\|		  |  |
		                  V		  V  |
		  bfqq1---------&amp;gt;bfqq2		  bfqq3
process ref:	   0		    2		    1&lt;/p&gt;
&lt;p&gt;3) bfqq2 merged to bfqq3:&lt;/p&gt;
&lt;p&gt;Process 1       Process 2	Process 3
		 (BIC1)          (BIC2)		 (BIC3)
	 here -&amp;gt; Λ                |		  |
		  \--------------\ \-------------\|
		                  V		  V
		  bfqq1---------&amp;gt;bfqq2----------&amp;gt;bfqq3
process ref:	   0		    1		    3&lt;/p&gt;
&lt;p&gt;In this case, IO from Process 1 will get bfqq2 from BIC1 first, and then
get bfqq3 through merge chain, and finially handle IO by bfqq3.
Howerver, current code will think bfqq2 is owned by BIC1, like initial
state, and set bfqq2-&amp;gt;bic to BIC1.&lt;/p&gt;
&lt;p&gt;bfq_insert_request
-&amp;gt; by Process 1
 bfqq = bfq_init_rq(rq)
  bfqq = bfq_get_bfqq_handle_split
   bfqq = bic_to_bfqq
   -&amp;gt; get bfqq2 from BIC1
 bfqq-&amp;gt;ref++
 rq-&amp;gt;elv.priv[0] = bic
 rq-&amp;gt;elv.priv[1] = bfqq
 if (bfqq_process_refs(bfqq) == 1)
  bfqq-&amp;gt;bic = bic
  -&amp;gt; record BIC1 to bfqq2&lt;/p&gt;
&lt;p&gt;__bfq_insert_request
   new_bfqq = bfq_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens RUGGEDCOM RST2428P, Siemens SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family, Siemens SCALANCE XCM-/XRM-/XCH-/XRH-300 family, Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;block, bfq: fix possible UAF for bfqq-&amp;gt;bic with merge chain&lt;/p&gt;
&lt;p&gt;1) initial state, three tasks:&lt;/p&gt;
&lt;p&gt;Process 1       Process 2	Process 3
		 (BIC1)          (BIC2)		 (BIC3)
		  |  Λ            |  Λ		  |  Λ
		  |  |            |  |		  |  |
		  V  |            V  |		  V  |
		  bfqq1           bfqq2		  bfqq3
process ref:	   1		    1		    1&lt;/p&gt;
&lt;p&gt;2) bfqq1 merged to bfqq2:&lt;/p&gt;
&lt;p&gt;Process 1       Process 2	Process 3
		 (BIC1)          (BIC2)		 (BIC3)
		  |               |		  |  Λ
		  \--------------\|		  |  |
		                  V		  V  |
		  bfqq1---------&amp;gt;bfqq2		  bfqq3
process ref:	   0		    2		    1&lt;/p&gt;
&lt;p&gt;3) bfqq2 merged to bfqq3:&lt;/p&gt;
&lt;p&gt;Process 1       Process 2	Process 3
		 (BIC1)          (BIC2)		 (BIC3)
	 here -&amp;gt; Λ                |		  |
		  \--------------\ \-------------\|
		                  V		  V
		  bfqq1---------&amp;gt;bfqq2----------&amp;gt;bfqq3
process ref:	   0		    1		    3&lt;/p&gt;
&lt;p&gt;In this case, IO from Process 1 will get bfqq2 from BIC1 first, and then
get bfqq3 through merge chain, and finially handle IO by bfqq3.
Howerver, current code will think bfqq2 is owned by BIC1, like initial
state, and set bfqq2-&amp;gt;bic to BIC1.&lt;/p&gt;
&lt;p&gt;bfq_insert_request
-&amp;gt; by Process 1
 bfqq = bfq_init_rq(rq)
  bfqq = bfq_get_bfqq_handle_split
   bfqq = bic_to_bfqq
   -&amp;gt; get bfqq2 from BIC1
 bfqq-&amp;gt;ref++
 rq-&amp;gt;elv.priv[0] = bic
 rq-&amp;gt;elv.priv[1] = bfqq
 if (bfqq_process_refs(bfqq) == 1)
  bfqq-&amp;gt;bic = bic
  -&amp;gt; record BIC1 to bfqq2&lt;/p&gt;
&lt;p&gt;__bfq_insert_request
   new_bfqq = bfq_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-47706</guid>
    </item>
  </channel>
</rss>
