<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 05:49:54 +0000</lastBuildDate>
    <item>
      <title>CVE-2022-48649 — mm/slab_common: fix possible double free of kmem_cache</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2022-48649</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/slab_common: fix possible double free of kmem_cache&lt;/p&gt;
&lt;p&gt;When doing slub_debug test, kfence&amp;#39;s &amp;#39;test_memcache_typesafe_by_rcu&amp;#39;
kunit test case cause a use-after-free error:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: use-after-free in kobject_del+0x14/0x30
  Read of size 8 at addr ffff888007679090 by task kunit_try_catch/261&lt;/p&gt;
&lt;p&gt;CPU: 1 PID: 261 Comm: kunit_try_catch Tainted: G    B            N 6.0.0-rc5-next-20220916 #17
  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
  Call Trace:
   &amp;lt;TASK&amp;gt;
   dump_stack_lvl+0x34/0x48
   print_address_description.constprop.0+0x87/0x2a5
   print_report+0x103/0x1ed
   kasan_report+0xb7/0x140
   kobject_del+0x14/0x30
   kmem_cache_destroy+0x130/0x170
   test_exit+0x1a/0x30
   kunit_try_run_case+0xad/0xc0
   kunit_generic_run_threadfn_adapter+0x26/0x50
   kthread+0x17b/0x1b0
   &amp;lt;/TASK&amp;gt;&lt;/p&gt;
&lt;p&gt;The cause is inside kmem_cache_destroy():&lt;/p&gt;
&lt;p&gt;kmem_cache_destroy
    acquire lock/mutex
    shutdown_cache
        schedule_work(kmem_cache_release) (if RCU flag set)
    release lock/mutex
    kmem_cache_release (if RCU flag not set)&lt;/p&gt;
&lt;p&gt;In some certain timing, the scheduled work could be run before
the next RCU flag checking, which can then get a wrong value
and lead to double kmem_cache_release().&lt;/p&gt;
&lt;p&gt;Fix it by caching the RCU flag inside protected area, just like &amp;#39;refcnt&amp;#39;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;mm/slab_common: fix possible double free of kmem_cache&lt;/p&gt;
&lt;p&gt;When doing slub_debug test, kfence&amp;#39;s &amp;#39;test_memcache_typesafe_by_rcu&amp;#39;
kunit test case cause a use-after-free error:&lt;/p&gt;
&lt;p&gt;BUG: KASAN: use-after-free in kobject_del+0x14/0x30
  Read of size 8 at addr ffff888007679090 by task kunit_try_catch/261&lt;/p&gt;
&lt;p&gt;CPU: 1 PID: 261 Comm: kunit_try_catch Tainted: G    B            N 6.0.0-rc5-next-20220916 #17
  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
  Call Trace:
   &amp;lt;TASK&amp;gt;
   dump_stack_lvl+0x34/0x48
   print_address_description.constprop.0+0x87/0x2a5
   print_report+0x103/0x1ed
   kasan_report+0xb7/0x140
   kobject_del+0x14/0x30
   kmem_cache_destroy+0x130/0x170
   test_exit+0x1a/0x30
   kunit_try_run_case+0xad/0xc0
   kunit_generic_run_threadfn_adapter+0x26/0x50
   kthread+0x17b/0x1b0
   &amp;lt;/TASK&amp;gt;&lt;/p&gt;
&lt;p&gt;The cause is inside kmem_cache_destroy():&lt;/p&gt;
&lt;p&gt;kmem_cache_destroy
    acquire lock/mutex
    shutdown_cache
        schedule_work(kmem_cache_release) (if RCU flag set)
    release lock/mutex
    kmem_cache_release (if RCU flag not set)&lt;/p&gt;
&lt;p&gt;In some certain timing, the scheduled work could be run before
the next RCU flag checking, which can then get a wrong value
and lead to double kmem_cache_release().&lt;/p&gt;
&lt;p&gt;Fix it by caching the RCU flag inside protected area, just like &amp;#39;refcnt&amp;#39;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2022-48649</guid>
    </item>
  </channel>
</rss>
