<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 20:07:26 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-50483 — net: enetc: avoid buffer leaks on xdp_do_redirect() failure</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-50483</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: enetc: avoid buffer leaks on xdp_do_redirect() failure&lt;/p&gt;
&lt;p&gt;Before enetc_clean_rx_ring_xdp() calls xdp_do_redirect(), each software
BD in the RX ring between index orig_i and i can have one of 2 refcount
values on its page.&lt;/p&gt;
&lt;p&gt;We are the owner of the current buffer that is being processed, so the
refcount will be at least 1.&lt;/p&gt;
&lt;p&gt;If the current owner of the buffer at the diametrically opposed index
in the RX ring (i.o.w, the other half of this page) has not yet called
kfree(), this page&amp;#39;s refcount could even be 2.&lt;/p&gt;
&lt;p&gt;enetc_page_reusable() in enetc_flip_rx_buff() tests for the page
refcount against 1, and [ if it&amp;#39;s 2 ] does not attempt to reuse it.&lt;/p&gt;
&lt;p&gt;But if enetc_flip_rx_buff() is put after the xdp_do_redirect() call,
the page refcount can have one of 3 values. It can also be 0, if there
is no owner of the other page half, and xdp_do_redirect() for this
buffer ran so far that it triggered a flush of the devmap/cpumap bulk
queue, and the consumers of those bulk queues also freed the buffer,
all by the time xdp_do_redirect() returns the execution back to enetc.&lt;/p&gt;
&lt;p&gt;This is the reason why enetc_flip_rx_buff() is called before
xdp_do_redirect(), but there is a big flaw with that reasoning:
enetc_flip_rx_buff() will set rx_swbd-&amp;gt;page = NULL on both sides of the
enetc_page_reusable() branch, and if xdp_do_redirect() returns an error,
we call enetc_xdp_free(), which does not deal gracefully with that.&lt;/p&gt;
&lt;p&gt;In fact, what happens i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;net: enetc: avoid buffer leaks on xdp_do_redirect() failure&lt;/p&gt;
&lt;p&gt;Before enetc_clean_rx_ring_xdp() calls xdp_do_redirect(), each software
BD in the RX ring between index orig_i and i can have one of 2 refcount
values on its page.&lt;/p&gt;
&lt;p&gt;We are the owner of the current buffer that is being processed, so the
refcount will be at least 1.&lt;/p&gt;
&lt;p&gt;If the current owner of the buffer at the diametrically opposed index
in the RX ring (i.o.w, the other half of this page) has not yet called
kfree(), this page&amp;#39;s refcount could even be 2.&lt;/p&gt;
&lt;p&gt;enetc_page_reusable() in enetc_flip_rx_buff() tests for the page
refcount against 1, and [ if it&amp;#39;s 2 ] does not attempt to reuse it.&lt;/p&gt;
&lt;p&gt;But if enetc_flip_rx_buff() is put after the xdp_do_redirect() call,
the page refcount can have one of 3 values. It can also be 0, if there
is no owner of the other page half, and xdp_do_redirect() for this
buffer ran so far that it triggered a flush of the devmap/cpumap bulk
queue, and the consumers of those bulk queues also freed the buffer,
all by the time xdp_do_redirect() returns the execution back to enetc.&lt;/p&gt;
&lt;p&gt;This is the reason why enetc_flip_rx_buff() is called before
xdp_do_redirect(), but there is a big flaw with that reasoning:
enetc_flip_rx_buff() will set rx_swbd-&amp;gt;page = NULL on both sides of the
enetc_page_reusable() branch, and if xdp_do_redirect() returns an error,
we call enetc_xdp_free(), which does not deal gracefully with that.&lt;/p&gt;
&lt;p&gt;In fact, what happens i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-50483</guid>
    </item>
  </channel>
</rss>
