<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 05:12:16 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-49605 — igc: Reinstate IGC_REMOVED logic and implement it properly</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-49605</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;igc: Reinstate IGC_REMOVED logic and implement it properly&lt;/p&gt;
&lt;p&gt;The initially merged version of the igc driver code (via commit
146740f9abc4, &amp;#34;igc: Add support for PF&amp;#34;) contained the following
IGC_REMOVED checks in the igc_rd32/wr32() MMIO accessors:&lt;/p&gt;
&lt;p&gt;u32 igc_rd32(struct igc_hw *hw, u32 reg)
	{
		u8 __iomem *hw_addr = READ_ONCE(hw-&amp;gt;hw_addr);
		u32 value = 0;&lt;/p&gt;
&lt;p&gt;if (IGC_REMOVED(hw_addr))
			return ~value;&lt;/p&gt;
&lt;p&gt;value = readl(&amp;amp;hw_addr[reg]);&lt;/p&gt;
&lt;p&gt;/* reads should not return all F&amp;#39;s */
		if (!(~value) &amp;amp;&amp;amp; (!reg || !(~readl(hw_addr))))
			hw-&amp;gt;hw_addr = NULL;&lt;/p&gt;
&lt;p&gt;return value;
	}&lt;/p&gt;
&lt;p&gt;And:&lt;/p&gt;
&lt;p&gt;#define wr32(reg, val) \
	do { \
		u8 __iomem *hw_addr = READ_ONCE((hw)-&amp;gt;hw_addr); \
		if (!IGC_REMOVED(hw_addr)) \
			writel((val), &amp;amp;hw_addr[(reg)]); \
	} while (0)&lt;/p&gt;
&lt;p&gt;E.g. igb has similar checks in its MMIO accessors, and has a similar
macro E1000_REMOVED, which is implemented as follows:&lt;/p&gt;
&lt;p&gt;#define E1000_REMOVED(h) unlikely(!(h))&lt;/p&gt;
&lt;p&gt;These checks serve to detect and take note of an 0xffffffff MMIO read
return from the device, which can be caused by a PCIe link flap or some
other kind of PCI bus error, and to avoid performing MMIO reads and
writes from that point onwards.&lt;/p&gt;
&lt;p&gt;However, the IGC_REMOVED macro was not originally implemented:&lt;/p&gt;
&lt;p&gt;#ifndef IGC_REMOVED
	#define IGC_REMOVED(a) (0)
	#endif /* IGC_REMOVED */&lt;/p&gt;
&lt;p&gt;This led to the IGC_REMOVED logic to be removed entirely in a
subsequent commit (commit 3c215fb18e70, &amp;#34;igc: remove IGC_REMOVED
function…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;igc: Reinstate IGC_REMOVED logic and implement it properly&lt;/p&gt;
&lt;p&gt;The initially merged version of the igc driver code (via commit
146740f9abc4, &amp;#34;igc: Add support for PF&amp;#34;) contained the following
IGC_REMOVED checks in the igc_rd32/wr32() MMIO accessors:&lt;/p&gt;
&lt;p&gt;u32 igc_rd32(struct igc_hw *hw, u32 reg)
	{
		u8 __iomem *hw_addr = READ_ONCE(hw-&amp;gt;hw_addr);
		u32 value = 0;&lt;/p&gt;
&lt;p&gt;if (IGC_REMOVED(hw_addr))
			return ~value;&lt;/p&gt;
&lt;p&gt;value = readl(&amp;amp;hw_addr[reg]);&lt;/p&gt;
&lt;p&gt;/* reads should not return all F&amp;#39;s */
		if (!(~value) &amp;amp;&amp;amp; (!reg || !(~readl(hw_addr))))
			hw-&amp;gt;hw_addr = NULL;&lt;/p&gt;
&lt;p&gt;return value;
	}&lt;/p&gt;
&lt;p&gt;And:&lt;/p&gt;
&lt;p&gt;#define wr32(reg, val) \
	do { \
		u8 __iomem *hw_addr = READ_ONCE((hw)-&amp;gt;hw_addr); \
		if (!IGC_REMOVED(hw_addr)) \
			writel((val), &amp;amp;hw_addr[(reg)]); \
	} while (0)&lt;/p&gt;
&lt;p&gt;E.g. igb has similar checks in its MMIO accessors, and has a similar
macro E1000_REMOVED, which is implemented as follows:&lt;/p&gt;
&lt;p&gt;#define E1000_REMOVED(h) unlikely(!(h))&lt;/p&gt;
&lt;p&gt;These checks serve to detect and take note of an 0xffffffff MMIO read
return from the device, which can be caused by a PCIe link flap or some
other kind of PCI bus error, and to avoid performing MMIO reads and
writes from that point onwards.&lt;/p&gt;
&lt;p&gt;However, the IGC_REMOVED macro was not originally implemented:&lt;/p&gt;
&lt;p&gt;#ifndef IGC_REMOVED
	#define IGC_REMOVED(a) (0)
	#endif /* IGC_REMOVED */&lt;/p&gt;
&lt;p&gt;This led to the IGC_REMOVED logic to be removed entirely in a
subsequent commit (commit 3c215fb18e70, &amp;#34;igc: remove IGC_REMOVED
function…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-49605</guid>
    </item>
    <item>
      <title>RHSA-2022:7683 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:7683</link>
      <description>&lt;p&gt;kernel: off-path attacker may inject data or terminate victim&amp;#39;s TCP session kernel: race condition in VT_RESIZEX ioctl when vc_cons[i].d is already NULL leading to NULL pointer dereference kernel: use-after-free vulnerability in function sco_sock_sendmsg() kernel: memory leak for large arguments in video_usercopy function in drivers/media/v4l2-core/v4l2-ioctl.c kernel: mm/damon/dbgfs: protect targets destructions with kdamond_lock kernel: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page() kernel: veth: ensure skb entering GRO are not cloned. kernel: inet: fully convert sk-&amp;gt;sk_rx_dst to RCU rules kernel: NFSD: Fix READDIR buffer overflow kernel: cpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_init kernel: nvme-rdma: destroy cm id before destroy qp to avoid use after free kernel: regmap: Fix possible double-free in regcache_rbtree_exit() kernel: ethtool: do not perform operations on net devices being unregistered kernel: scsi: scsi_debug: Fix type in min_t to avoid stack OOB kernel: KVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU kernel: udmabuf: validate ubuf-&amp;gt;pagecount kernel: drm/virtio: Ensure that objs is not NULL in virtio_gpu_array_put_free() kernel: smb2_ioctl_query_info NULL pointer dereference kernel: NULL pointer dereference in udf_expand_file_adinicbdue() during writeback kernel: swiotlb information leak with DMA_FROM_DEVICE kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM k…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: off-path attacker may inject data or terminate victim&amp;#39;s TCP session kernel: race condition in VT_RESIZEX ioctl when vc_cons[i].d is already NULL leading to NULL pointer dereference kernel: use-after-free vulnerability in function sco_sock_sendmsg() kernel: memory leak for large arguments in video_usercopy function in drivers/media/v4l2-core/v4l2-ioctl.c kernel: mm/damon/dbgfs: protect targets destructions with kdamond_lock kernel: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page() kernel: veth: ensure skb entering GRO are not cloned. kernel: inet: fully convert sk-&amp;gt;sk_rx_dst to RCU rules kernel: NFSD: Fix READDIR buffer overflow kernel: cpufreq: CPPC: Fix potential memleak in cppc_cpufreq_cpu_init kernel: nvme-rdma: destroy cm id before destroy qp to avoid use after free kernel: regmap: Fix possible double-free in regcache_rbtree_exit() kernel: ethtool: do not perform operations on net devices being unregistered kernel: scsi: scsi_debug: Fix type in min_t to avoid stack OOB kernel: KVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU kernel: udmabuf: validate ubuf-&amp;gt;pagecount kernel: drm/virtio: Ensure that objs is not NULL in virtio_gpu_array_put_free() kernel: smb2_ioctl_query_info NULL pointer dereference kernel: NULL pointer dereference in udf_expand_file_adinicbdue() during writeback kernel: swiotlb information leak with DMA_FROM_DEVICE kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM k…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:7683</guid>
    </item>
  </channel>
</rss>
