<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 17:58:05 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-46933 — usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear.</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-46933</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear.&lt;/p&gt;
&lt;p&gt;ffs_data_clear is indirectly called from both ffs_fs_kill_sb and
ffs_ep0_release, so it ends up being called twice when userland closes ep0
and then unmounts f_fs.
If userland provided an eventfd along with function&amp;#39;s USB descriptors, it
ends up calling eventfd_ctx_put as many times, causing a refcount
underflow.
NULL-ify ffs_eventfd to prevent these extraneous eventfd_ctx_put calls.&lt;/p&gt;
&lt;p&gt;Also, set epfiles to NULL right after de-allocating it, for readability.&lt;/p&gt;
&lt;p&gt;For completeness, ffs_data_clear actually ends up being called thrice, the
last call being before the whole ffs structure gets freed, so when this
specific sequence happens there is a second underflow happening (but not
being reported):&lt;/p&gt;
&lt;p&gt;/sys/kernel/debug/tracing# modprobe usb_f_fs
/sys/kernel/debug/tracing# echo ffs_data_clear &amp;gt; set_ftrace_filter
/sys/kernel/debug/tracing# echo function &amp;gt; current_tracer
/sys/kernel/debug/tracing# echo 1 &amp;gt; tracing_on
(setup gadget, run and kill function userland process, teardown gadget)
/sys/kernel/debug/tracing# echo 0 &amp;gt; tracing_on
/sys/kernel/debug/tracing# cat trace
 smartcard-openp-436     [000] .....  1946.208786: ffs_data_clear &amp;lt;-ffs_data_closed
 smartcard-openp-431     [000] .....  1946.279147: ffs_data_clear &amp;lt;-ffs_data_closed
 smartcard-openp-431     [000] .n...  1946.905512: ffs_data_clear &amp;lt;-ffs_data_put&lt;/p&gt;
&lt;p&gt;Warning output corresponding to above trace:
[ 194…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear.&lt;/p&gt;
&lt;p&gt;ffs_data_clear is indirectly called from both ffs_fs_kill_sb and
ffs_ep0_release, so it ends up being called twice when userland closes ep0
and then unmounts f_fs.
If userland provided an eventfd along with function&amp;#39;s USB descriptors, it
ends up calling eventfd_ctx_put as many times, causing a refcount
underflow.
NULL-ify ffs_eventfd to prevent these extraneous eventfd_ctx_put calls.&lt;/p&gt;
&lt;p&gt;Also, set epfiles to NULL right after de-allocating it, for readability.&lt;/p&gt;
&lt;p&gt;For completeness, ffs_data_clear actually ends up being called thrice, the
last call being before the whole ffs structure gets freed, so when this
specific sequence happens there is a second underflow happening (but not
being reported):&lt;/p&gt;
&lt;p&gt;/sys/kernel/debug/tracing# modprobe usb_f_fs
/sys/kernel/debug/tracing# echo ffs_data_clear &amp;gt; set_ftrace_filter
/sys/kernel/debug/tracing# echo function &amp;gt; current_tracer
/sys/kernel/debug/tracing# echo 1 &amp;gt; tracing_on
(setup gadget, run and kill function userland process, teardown gadget)
/sys/kernel/debug/tracing# echo 0 &amp;gt; tracing_on
/sys/kernel/debug/tracing# cat trace
 smartcard-openp-436     [000] .....  1946.208786: ffs_data_clear &amp;lt;-ffs_data_closed
 smartcard-openp-431     [000] .....  1946.279147: ffs_data_clear &amp;lt;-ffs_data_closed
 smartcard-openp-431     [000] .n...  1946.905512: ffs_data_clear &amp;lt;-ffs_data_put&lt;/p&gt;
&lt;p&gt;Warning output corresponding to above trace:
[ 194…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-46933</guid>
    </item>
  </channel>
</rss>
