<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 16:14:14 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-49394 — blk-iolatency: Fix inflight count imbalances and IO hangs on offline</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-49394</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;blk-iolatency: Fix inflight count imbalances and IO hangs on offline&lt;/p&gt;
&lt;p&gt;iolatency needs to track the number of inflight IOs per cgroup. As this
tracking can be expensive, it is disabled when no cgroup has iolatency
configured for the device. To ensure that the inflight counters stay
balanced, iolatency_set_limit() freezes the request_queue while manipulating
the enabled counter, which ensures that no IO is in flight and thus all
counters are zero.&lt;/p&gt;
&lt;p&gt;Unfortunately, iolatency_set_limit() isn&amp;#39;t the only place where the enabled
counter is manipulated. iolatency_pd_offline() can also dec the counter and
trigger disabling. As this disabling happens without freezing the q, this
can easily happen while some IOs are in flight and thus leak the counts.&lt;/p&gt;
&lt;p&gt;This can be easily demonstrated by turning on iolatency on an one empty
cgroup while IOs are in flight in other cgroups and then removing the
cgroup. Note that iolatency shouldn&amp;#39;t have been enabled elsewhere in the
system to ensure that removing the cgroup disables iolatency for the whole
device.&lt;/p&gt;
&lt;p&gt;The following keeps flipping on and off iolatency on sda:&lt;/p&gt;
&lt;p&gt;echo +io &amp;gt; /sys/fs/cgroup/cgroup.subtree_control
  while true; do
      mkdir -p /sys/fs/cgroup/test
      echo &amp;#39;8:0 target=100000&amp;#39; &amp;gt; /sys/fs/cgroup/test/io.latency
      sleep 1
      rmdir /sys/fs/cgroup/test
      sleep 1
  done&lt;/p&gt;
&lt;p&gt;and there&amp;#39;s concurrent fio generating direct rand reads:&lt;/p&gt;
&lt;p&gt;fio --name test --filename…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;blk-iolatency: Fix inflight count imbalances and IO hangs on offline&lt;/p&gt;
&lt;p&gt;iolatency needs to track the number of inflight IOs per cgroup. As this
tracking can be expensive, it is disabled when no cgroup has iolatency
configured for the device. To ensure that the inflight counters stay
balanced, iolatency_set_limit() freezes the request_queue while manipulating
the enabled counter, which ensures that no IO is in flight and thus all
counters are zero.&lt;/p&gt;
&lt;p&gt;Unfortunately, iolatency_set_limit() isn&amp;#39;t the only place where the enabled
counter is manipulated. iolatency_pd_offline() can also dec the counter and
trigger disabling. As this disabling happens without freezing the q, this
can easily happen while some IOs are in flight and thus leak the counts.&lt;/p&gt;
&lt;p&gt;This can be easily demonstrated by turning on iolatency on an one empty
cgroup while IOs are in flight in other cgroups and then removing the
cgroup. Note that iolatency shouldn&amp;#39;t have been enabled elsewhere in the
system to ensure that removing the cgroup disables iolatency for the whole
device.&lt;/p&gt;
&lt;p&gt;The following keeps flipping on and off iolatency on sda:&lt;/p&gt;
&lt;p&gt;echo +io &amp;gt; /sys/fs/cgroup/cgroup.subtree_control
  while true; do
      mkdir -p /sys/fs/cgroup/test
      echo &amp;#39;8:0 target=100000&amp;#39; &amp;gt; /sys/fs/cgroup/test/io.latency
      sleep 1
      rmdir /sys/fs/cgroup/test
      sleep 1
  done&lt;/p&gt;
&lt;p&gt;and there&amp;#39;s concurrent fio generating direct rand reads:&lt;/p&gt;
&lt;p&gt;fio --name test --filename…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-49394</guid>
    </item>
    <item>
      <title>RHSA-2022:8267 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:8267</link>
      <description>&lt;p&gt;kernel: off-path attacker may inject data or terminate victim&amp;#39;s TCP session kernel: use-after-free vulnerability in function sco_sock_sendmsg() kernel: fix &amp;#39;struct pid&amp;#39; leaks in &amp;#39;dbgfs_target_ids_write()&amp;#39; kernel: mm/damon/dbgfs: protect targets destructions with kdamond_lock kernel: veth: ensure skb entering GRO are not cloned. kernel: inet: fully convert sk-&amp;gt;sk_rx_dst to RCU rules kernel: irqchip/gic-v3-its: Fix potential VPE leak on error kernel: nvme-rdma: destroy cm id before destroy qp to avoid use after free kernel: ptp: Fix possible memory leak in ptp_clock_register() kernel: ethtool: do not perform operations on net devices being unregistered kernel: ethtool: ioctl: fix potential NULL deref in ethtool_set_coalesce() kernel: net: nexthop: fix null pointer dereference when IPv6 is not enabled kernel: scsi: scsi_debug: Fix type in min_t to avoid stack OOB kernel: KVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU kernel: Revert &amp;#34;Revert &amp;#34;block, bfq: honor already-setup queue merges&amp;#34;&amp;#34; kernel: udmabuf: validate ubuf-&amp;gt;pagecount kernel: drm/virtio: Ensure that objs is not NULL in virtio_gpu_array_put_free() kernel: smb2_ioctl_query_info NULL pointer dereference kernel: NULL pointer dereference in udf_expand_file_adinicbdue() during writeback kernel: swiotlb information leak with DMA_FROM_DEVICE kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM kernel: race condition in snd_pcm_hw_free leading to use-after-free kern…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel: off-path attacker may inject data or terminate victim&amp;#39;s TCP session kernel: use-after-free vulnerability in function sco_sock_sendmsg() kernel: fix &amp;#39;struct pid&amp;#39; leaks in &amp;#39;dbgfs_target_ids_write()&amp;#39; kernel: mm/damon/dbgfs: protect targets destructions with kdamond_lock kernel: veth: ensure skb entering GRO are not cloned. kernel: inet: fully convert sk-&amp;gt;sk_rx_dst to RCU rules kernel: irqchip/gic-v3-its: Fix potential VPE leak on error kernel: nvme-rdma: destroy cm id before destroy qp to avoid use after free kernel: ptp: Fix possible memory leak in ptp_clock_register() kernel: ethtool: do not perform operations on net devices being unregistered kernel: ethtool: ioctl: fix potential NULL deref in ethtool_set_coalesce() kernel: net: nexthop: fix null pointer dereference when IPv6 is not enabled kernel: scsi: scsi_debug: Fix type in min_t to avoid stack OOB kernel: KVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU kernel: Revert &amp;#34;Revert &amp;#34;block, bfq: honor already-setup queue merges&amp;#34;&amp;#34; kernel: udmabuf: validate ubuf-&amp;gt;pagecount kernel: drm/virtio: Ensure that objs is not NULL in virtio_gpu_array_put_free() kernel: smb2_ioctl_query_info NULL pointer dereference kernel: NULL pointer dereference in udf_expand_file_adinicbdue() during writeback kernel: swiotlb information leak with DMA_FROM_DEVICE kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM kernel: race condition in snd_pcm_hw_free leading to use-after-free kern…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:8267</guid>
    </item>
  </channel>
</rss>
