<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 12:40:28 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-47549 — sata_fsl: fix UAF in sata_fsl_port_stop when rmmod sata_fsl</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-47549</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;sata_fsl: fix UAF in sata_fsl_port_stop when rmmod sata_fsl&lt;/p&gt;
&lt;p&gt;When the `rmmod sata_fsl.ko` command is executed in the PPC64 GNU/Linux,
a bug is reported:
 ==================================================================
 BUG: Unable to handle kernel data access on read at 0x80000800805b502c
 Oops: Kernel access of bad area, sig: 11 [#1]
 NIP [c0000000000388a4] .ioread32+0x4/0x20
 LR [80000000000c6034] .sata_fsl_port_stop+0x44/0xe0 [sata_fsl]
 Call Trace:
  .free_irq+0x1c/0x4e0 (unreliable)
  .ata_host_stop+0x74/0xd0 [libata]
  .release_nodes+0x330/0x3f0
  .device_release_driver_internal+0x178/0x2c0
  .driver_detach+0x64/0xd0
  .bus_remove_driver+0x70/0xf0
  .driver_unregister+0x38/0x80
  .platform_driver_unregister+0x14/0x30
  .fsl_sata_driver_exit+0x18/0xa20 [sata_fsl]
  .__se_sys_delete_module+0x1ec/0x2d0
  .system_call_exception+0xfc/0x1f0
  system_call_common+0xf8/0x200
 ==================================================================&lt;/p&gt;
&lt;p&gt;The triggering of the BUG is shown in the following stack:&lt;/p&gt;
&lt;p&gt;driver_detach
  device_release_driver_internal
    __device_release_driver
      drv-&amp;gt;remove(dev) --&amp;gt; platform_drv_remove/platform_remove
        drv-&amp;gt;remove(dev) --&amp;gt; sata_fsl_remove
          iounmap(host_priv-&amp;gt;hcr_base);			&amp;lt;---- unmap
          kfree(host_priv);                             &amp;lt;---- free
      devres_release_all
        release_nodes
          dr-&amp;gt;node.release(dev, dr-&amp;gt;data) --&amp;gt; ata_host_stop…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;sata_fsl: fix UAF in sata_fsl_port_stop when rmmod sata_fsl&lt;/p&gt;
&lt;p&gt;When the `rmmod sata_fsl.ko` command is executed in the PPC64 GNU/Linux,
a bug is reported:
 ==================================================================
 BUG: Unable to handle kernel data access on read at 0x80000800805b502c
 Oops: Kernel access of bad area, sig: 11 [#1]
 NIP [c0000000000388a4] .ioread32+0x4/0x20
 LR [80000000000c6034] .sata_fsl_port_stop+0x44/0xe0 [sata_fsl]
 Call Trace:
  .free_irq+0x1c/0x4e0 (unreliable)
  .ata_host_stop+0x74/0xd0 [libata]
  .release_nodes+0x330/0x3f0
  .device_release_driver_internal+0x178/0x2c0
  .driver_detach+0x64/0xd0
  .bus_remove_driver+0x70/0xf0
  .driver_unregister+0x38/0x80
  .platform_driver_unregister+0x14/0x30
  .fsl_sata_driver_exit+0x18/0xa20 [sata_fsl]
  .__se_sys_delete_module+0x1ec/0x2d0
  .system_call_exception+0xfc/0x1f0
  system_call_common+0xf8/0x200
 ==================================================================&lt;/p&gt;
&lt;p&gt;The triggering of the BUG is shown in the following stack:&lt;/p&gt;
&lt;p&gt;driver_detach
  device_release_driver_internal
    __device_release_driver
      drv-&amp;gt;remove(dev) --&amp;gt; platform_drv_remove/platform_remove
        drv-&amp;gt;remove(dev) --&amp;gt; sata_fsl_remove
          iounmap(host_priv-&amp;gt;hcr_base);			&amp;lt;---- unmap
          kfree(host_priv);                             &amp;lt;---- free
      devres_release_all
        release_nodes
          dr-&amp;gt;node.release(dev, dr-&amp;gt;data) --&amp;gt; ata_host_stop…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-47549</guid>
    </item>
  </channel>
</rss>
