<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 19:58:23 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-49394 — blk-iolatency: Fix inflight count imbalances and IO hangs on offline</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-49394</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;blk-iolatency: Fix inflight count imbalances and IO hangs on offline&lt;/p&gt;
&lt;p&gt;iolatency needs to track the number of inflight IOs per cgroup. As this
tracking can be expensive, it is disabled when no cgroup has iolatency
configured for the device. To ensure that the inflight counters stay
balanced, iolatency_set_limit() freezes the request_queue while manipulating
the enabled counter, which ensures that no IO is in flight and thus all
counters are zero.&lt;/p&gt;
&lt;p&gt;Unfortunately, iolatency_set_limit() isn&amp;#39;t the only place where the enabled
counter is manipulated. iolatency_pd_offline() can also dec the counter and
trigger disabling. As this disabling happens without freezing the q, this
can easily happen while some IOs are in flight and thus leak the counts.&lt;/p&gt;
&lt;p&gt;This can be easily demonstrated by turning on iolatency on an one empty
cgroup while IOs are in flight in other cgroups and then removing the
cgroup. Note that iolatency shouldn&amp;#39;t have been enabled elsewhere in the
system to ensure that removing the cgroup disables iolatency for the whole
device.&lt;/p&gt;
&lt;p&gt;The following keeps flipping on and off iolatency on sda:&lt;/p&gt;
&lt;p&gt;echo +io &amp;gt; /sys/fs/cgroup/cgroup.subtree_control
  while true; do
      mkdir -p /sys/fs/cgroup/test
      echo &amp;#39;8:0 target=100000&amp;#39; &amp;gt; /sys/fs/cgroup/test/io.latency
      sleep 1
      rmdir /sys/fs/cgroup/test
      sleep 1
  done&lt;/p&gt;
&lt;p&gt;and there&amp;#39;s concurrent fio generating direct rand reads:&lt;/p&gt;
&lt;p&gt;fio --name test --filename…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;blk-iolatency: Fix inflight count imbalances and IO hangs on offline&lt;/p&gt;
&lt;p&gt;iolatency needs to track the number of inflight IOs per cgroup. As this
tracking can be expensive, it is disabled when no cgroup has iolatency
configured for the device. To ensure that the inflight counters stay
balanced, iolatency_set_limit() freezes the request_queue while manipulating
the enabled counter, which ensures that no IO is in flight and thus all
counters are zero.&lt;/p&gt;
&lt;p&gt;Unfortunately, iolatency_set_limit() isn&amp;#39;t the only place where the enabled
counter is manipulated. iolatency_pd_offline() can also dec the counter and
trigger disabling. As this disabling happens without freezing the q, this
can easily happen while some IOs are in flight and thus leak the counts.&lt;/p&gt;
&lt;p&gt;This can be easily demonstrated by turning on iolatency on an one empty
cgroup while IOs are in flight in other cgroups and then removing the
cgroup. Note that iolatency shouldn&amp;#39;t have been enabled elsewhere in the
system to ensure that removing the cgroup disables iolatency for the whole
device.&lt;/p&gt;
&lt;p&gt;The following keeps flipping on and off iolatency on sda:&lt;/p&gt;
&lt;p&gt;echo +io &amp;gt; /sys/fs/cgroup/cgroup.subtree_control
  while true; do
      mkdir -p /sys/fs/cgroup/test
      echo &amp;#39;8:0 target=100000&amp;#39; &amp;gt; /sys/fs/cgroup/test/io.latency
      sleep 1
      rmdir /sys/fs/cgroup/test
      sleep 1
  done&lt;/p&gt;
&lt;p&gt;and there&amp;#39;s concurrent fio generating direct rand reads:&lt;/p&gt;
&lt;p&gt;fio --name test --filename…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-49394</guid>
    </item>
  </channel>
</rss>
