<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 17:50:32 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-49400 — md: Don't set mddev private to NULL in raid0 pers-&gt;free</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-49400</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;md: Don&amp;#39;t set mddev private to NULL in raid0 pers-&amp;gt;free&lt;/p&gt;
&lt;p&gt;In normal stop process, it does like this:
   do_md_stop
      |
   __md_stop (pers-&amp;gt;free(); mddev-&amp;gt;private=NULL)
      |
   md_free (free mddev)
__md_stop sets mddev-&amp;gt;private to NULL after pers-&amp;gt;free. The raid device
will be stopped and mddev memory is free. But in reshape, it doesn&amp;#39;t
free the mddev and mddev will still be used in new raid.&lt;/p&gt;
&lt;p&gt;In reshape, it first sets mddev-&amp;gt;private to new_pers and then runs
old_pers-&amp;gt;free(). Now raid0 sets mddev-&amp;gt;private to NULL in raid0_free.
The new raid can&amp;#39;t work anymore. It will panic when dereference
mddev-&amp;gt;private because of NULL pointer dereference.&lt;/p&gt;
&lt;p&gt;It can panic like this:
[63010.814972] kernel BUG at drivers/md/raid10.c:928!
[63010.819778] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI
[63010.825011] CPU: 3 PID: 44437 Comm: md0_resync Kdump: loaded Not tainted 5.14.0-86.el9.x86_64 #1
[63010.833789] Hardware name: Dell Inc. PowerEdge R6415/07YXFK, BIOS 1.15.0 09/11/2020
[63010.841440] RIP: 0010:raise_barrier+0x161/0x170 [raid10]
[63010.865508] RSP: 0018:ffffc312408bbc10 EFLAGS: 00010246
[63010.870734] RAX: 0000000000000000 RBX: ffffa00bf7d39800 RCX: 0000000000000000
[63010.877866] RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffffa00bf7d39800
[63010.884999] RBP: 0000000000000000 R08: fffffa4945e74400 R09: 0000000000000000
[63010.892132] R10: ffffa00eed02f798 R11: 0000000000000000 R12: ffffa00bbc435200
[63010…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;md: Don&amp;#39;t set mddev private to NULL in raid0 pers-&amp;gt;free&lt;/p&gt;
&lt;p&gt;In normal stop process, it does like this:
   do_md_stop
      |
   __md_stop (pers-&amp;gt;free(); mddev-&amp;gt;private=NULL)
      |
   md_free (free mddev)
__md_stop sets mddev-&amp;gt;private to NULL after pers-&amp;gt;free. The raid device
will be stopped and mddev memory is free. But in reshape, it doesn&amp;#39;t
free the mddev and mddev will still be used in new raid.&lt;/p&gt;
&lt;p&gt;In reshape, it first sets mddev-&amp;gt;private to new_pers and then runs
old_pers-&amp;gt;free(). Now raid0 sets mddev-&amp;gt;private to NULL in raid0_free.
The new raid can&amp;#39;t work anymore. It will panic when dereference
mddev-&amp;gt;private because of NULL pointer dereference.&lt;/p&gt;
&lt;p&gt;It can panic like this:
[63010.814972] kernel BUG at drivers/md/raid10.c:928!
[63010.819778] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI
[63010.825011] CPU: 3 PID: 44437 Comm: md0_resync Kdump: loaded Not tainted 5.14.0-86.el9.x86_64 #1
[63010.833789] Hardware name: Dell Inc. PowerEdge R6415/07YXFK, BIOS 1.15.0 09/11/2020
[63010.841440] RIP: 0010:raise_barrier+0x161/0x170 [raid10]
[63010.865508] RSP: 0018:ffffc312408bbc10 EFLAGS: 00010246
[63010.870734] RAX: 0000000000000000 RBX: ffffa00bf7d39800 RCX: 0000000000000000
[63010.877866] RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffffa00bf7d39800
[63010.884999] RBP: 0000000000000000 R08: fffffa4945e74400 R09: 0000000000000000
[63010.892132] R10: ffffa00eed02f798 R11: 0000000000000000 R12: ffffa00bbc435200
[63010…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-49400</guid>
    </item>
  </channel>
</rss>
