<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 19:20:42 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-53044 — net/sched: sch_api: fix xa_insert() error path in tcf_block_get_ext()</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-53044</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: sch_api: fix xa_insert() error path in tcf_block_get_ext()&lt;/p&gt;
&lt;p&gt;This command:&lt;/p&gt;
&lt;p&gt;$ tc qdisc replace dev eth0 ingress_block 1 egress_block 1 clsact
Error: block dev insert failed: -EBUSY.&lt;/p&gt;
&lt;p&gt;fails because user space requests the same block index to be set for
both ingress and egress.&lt;/p&gt;
&lt;p&gt;[ side note, I don&amp;#39;t think it even failed prior to commit 913b47d3424e
  (&amp;#34;net/sched: Introduce tc block netdev tracking infra&amp;#34;), because this
  is a command from an old set of notes of mine which used to work, but
  alas, I did not scientifically bisect this ]&lt;/p&gt;
&lt;p&gt;The problem is not that it fails, but rather, that the second time
around, it fails differently (and irrecoverably):&lt;/p&gt;
&lt;p&gt;$ tc qdisc replace dev eth0 ingress_block 1 egress_block 1 clsact
Error: dsa_core: Flow block cb is busy.&lt;/p&gt;
&lt;p&gt;[ another note: the extack is added by me for illustration purposes.
  the context of the problem is that clsact_init() obtains the same
  &amp;amp;q-&amp;gt;ingress_block pointer as &amp;amp;q-&amp;gt;egress_block, and since we call
  tcf_block_get_ext() on both of them, &amp;#34;dev&amp;#34; will be added to the
  block-&amp;gt;ports xarray twice, thus failing the operation: once through
  the ingress block pointer, and once again through the egress block
  pointer. the problem itself is that when xa_insert() fails, we have
  emitted a FLOW_BLOCK_BIND command through ndo_setup_tc(), but the
  offload never sees a corresponding FLOW_BLOCK_UNBIND. ]&lt;/p&gt;
&lt;p&gt;Even correcting the bad user input, we still can…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net/sched: sch_api: fix xa_insert() error path in tcf_block_get_ext()&lt;/p&gt;
&lt;p&gt;This command:&lt;/p&gt;
&lt;p&gt;$ tc qdisc replace dev eth0 ingress_block 1 egress_block 1 clsact
Error: block dev insert failed: -EBUSY.&lt;/p&gt;
&lt;p&gt;fails because user space requests the same block index to be set for
both ingress and egress.&lt;/p&gt;
&lt;p&gt;[ side note, I don&amp;#39;t think it even failed prior to commit 913b47d3424e
  (&amp;#34;net/sched: Introduce tc block netdev tracking infra&amp;#34;), because this
  is a command from an old set of notes of mine which used to work, but
  alas, I did not scientifically bisect this ]&lt;/p&gt;
&lt;p&gt;The problem is not that it fails, but rather, that the second time
around, it fails differently (and irrecoverably):&lt;/p&gt;
&lt;p&gt;$ tc qdisc replace dev eth0 ingress_block 1 egress_block 1 clsact
Error: dsa_core: Flow block cb is busy.&lt;/p&gt;
&lt;p&gt;[ another note: the extack is added by me for illustration purposes.
  the context of the problem is that clsact_init() obtains the same
  &amp;amp;q-&amp;gt;ingress_block pointer as &amp;amp;q-&amp;gt;egress_block, and since we call
  tcf_block_get_ext() on both of them, &amp;#34;dev&amp;#34; will be added to the
  block-&amp;gt;ports xarray twice, thus failing the operation: once through
  the ingress block pointer, and once again through the egress block
  pointer. the problem itself is that when xa_insert() fails, we have
  emitted a FLOW_BLOCK_BIND command through ndo_setup_tc(), but the
  offload never sees a corresponding FLOW_BLOCK_UNBIND. ]&lt;/p&gt;
&lt;p&gt;Even correcting the bad user input, we still can…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-53044</guid>
    </item>
  </channel>
</rss>
