<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 18:34:22 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-45003 — vfs: Don't evict inode under the inode lru traversing context</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-45003</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vfs: Don&amp;#39;t evict inode under the inode lru traversing context&lt;/p&gt;
&lt;p&gt;The inode reclaiming process(See function prune_icache_sb) collects all
reclaimable inodes and mark them with I_FREEING flag at first, at that
time, other processes will be stuck if they try getting these inodes
(See function find_inode_fast), then the reclaiming process destroy the
inodes by function dispose_list(). Some filesystems(eg. ext4 with
ea_inode feature, ubifs with xattr) may do inode lookup in the inode
evicting callback function, if the inode lookup is operated under the
inode lru traversing context, deadlock problems may happen.&lt;/p&gt;
&lt;p&gt;Case 1: In function ext4_evict_inode(), the ea inode lookup could happen
        if ea_inode feature is enabled, the lookup process will be stuck
	under the evicting context like this:&lt;/p&gt;
&lt;p&gt;1. File A has inode i_reg and an ea inode i_ea
 2. getfattr(A, xattr_buf) // i_ea is added into lru // lru-&amp;gt;i_ea
 3. Then, following three processes running like this:&lt;/p&gt;
&lt;p&gt;PA                              PB
 echo 2 &amp;gt; /proc/sys/vm/drop_caches
  shrink_slab
   prune_dcache_sb
   // i_reg is added into lru, lru-&amp;gt;i_ea-&amp;gt;i_reg
   prune_icache_sb
    list_lru_walk_one
     inode_lru_isolate
      i_ea-&amp;gt;i_state |= I_FREEING // set inode state
     inode_lru_isolate
      __iget(i_reg)
      spin_unlock(&amp;amp;i_reg-&amp;gt;i_lock)
      spin_unlock(lru_lock)
                                     rm file A…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;vfs: Don&amp;#39;t evict inode under the inode lru traversing context&lt;/p&gt;
&lt;p&gt;The inode reclaiming process(See function prune_icache_sb) collects all
reclaimable inodes and mark them with I_FREEING flag at first, at that
time, other processes will be stuck if they try getting these inodes
(See function find_inode_fast), then the reclaiming process destroy the
inodes by function dispose_list(). Some filesystems(eg. ext4 with
ea_inode feature, ubifs with xattr) may do inode lookup in the inode
evicting callback function, if the inode lookup is operated under the
inode lru traversing context, deadlock problems may happen.&lt;/p&gt;
&lt;p&gt;Case 1: In function ext4_evict_inode(), the ea inode lookup could happen
        if ea_inode feature is enabled, the lookup process will be stuck
	under the evicting context like this:&lt;/p&gt;
&lt;p&gt;1. File A has inode i_reg and an ea inode i_ea
 2. getfattr(A, xattr_buf) // i_ea is added into lru // lru-&amp;gt;i_ea
 3. Then, following three processes running like this:&lt;/p&gt;
&lt;p&gt;PA                              PB
 echo 2 &amp;gt; /proc/sys/vm/drop_caches
  shrink_slab
   prune_dcache_sb
   // i_reg is added into lru, lru-&amp;gt;i_ea-&amp;gt;i_reg
   prune_icache_sb
    list_lru_walk_one
     inode_lru_isolate
      i_ea-&amp;gt;i_state |= I_FREEING // set inode state
     inode_lru_isolate
      __iget(i_reg)
      spin_unlock(&amp;amp;i_reg-&amp;gt;i_lock)
      spin_unlock(lru_lock)
                                     rm file A…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-45003</guid>
    </item>
    <item>
      <title>USN-7088-1 — linux, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4 vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-7088-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: linux-gcp-5.4, Ubuntu:Pro:18.04:LTS: linux-hwe-5.4, Ubuntu:Pro:18.04:LTS: linux-ibm-5.4, Ubuntu:20.04:LTS: linux, Ubuntu:20.04:LTS: linux-gcp, Ubuntu:20.04:LTS: linux-gkeop, Ubuntu:20.04:LTS: linux-ibm&lt;/p&gt;
&lt;p&gt;Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the Linux
kernel contained an integer overflow vulnerability. A local attacker could
use this to cause a denial of service (system crash). (CVE-2022-36402)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - PowerPC architecture;
  - User-Mode Linux (UML);
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Android drivers;
  - Serial ATA and Parallel ATA drivers;
  - ATM drivers;
  - Drivers core;
  - CPU frequency scaling framework;
  - Device frequency scaling framework;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - InfiniBand drivers;
  - Input Device core drivers;
  - IOMMU subsystem;
  - IRQ chip drivers;
  - ISDN/mISDN subsystem;
  - LED subsystem;
  - Multiple devices driver;
  - Media drivers;
  - EEPROM drivers;
  - VMware VMCI Driver;
  - MMC subsystem;
  - Network drivers;
  - Near Field Communication (NFC) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - Parport drivers;
  - PCI subsystem;
  - Pin controllers subsystem;
  - Remote Processor subsystem;
  - S/390 drivers;
  - SCSI drivers;
  - QCOM SoC drivers;
  - Direct Digital Synthesis drivers;
  - TTY drivers;
  - Userspace I/O drivers;
  - DesignWare USB3 driver;
  - USB subsystem;
  - BTRFS file system;
  - File sy…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: linux-gcp-5.4, Ubuntu:Pro:18.04:LTS: linux-hwe-5.4, Ubuntu:Pro:18.04:LTS: linux-ibm-5.4, Ubuntu:20.04:LTS: linux, Ubuntu:20.04:LTS: linux-gcp, Ubuntu:20.04:LTS: linux-gkeop, Ubuntu:20.04:LTS: linux-ibm&lt;/p&gt;
&lt;p&gt;Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the Linux
kernel contained an integer overflow vulnerability. A local attacker could
use this to cause a denial of service (system crash). (CVE-2022-36402)&lt;/p&gt;
&lt;p&gt;Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
  - ARM64 architecture;
  - PowerPC architecture;
  - User-Mode Linux (UML);
  - x86 architecture;
  - Block layer subsystem;
  - Cryptographic API;
  - Android drivers;
  - Serial ATA and Parallel ATA drivers;
  - ATM drivers;
  - Drivers core;
  - CPU frequency scaling framework;
  - Device frequency scaling framework;
  - GPU drivers;
  - HID subsystem;
  - Hardware monitoring drivers;
  - InfiniBand drivers;
  - Input Device core drivers;
  - IOMMU subsystem;
  - IRQ chip drivers;
  - ISDN/mISDN subsystem;
  - LED subsystem;
  - Multiple devices driver;
  - Media drivers;
  - EEPROM drivers;
  - VMware VMCI Driver;
  - MMC subsystem;
  - Network drivers;
  - Near Field Communication (NFC) drivers;
  - NVME drivers;
  - Device tree and open firmware driver;
  - Parport drivers;
  - PCI subsystem;
  - Pin controllers subsystem;
  - Remote Processor subsystem;
  - S/390 drivers;
  - SCSI drivers;
  - QCOM SoC drivers;
  - Direct Digital Synthesis drivers;
  - TTY drivers;
  - Userspace I/O drivers;
  - DesignWare USB3 driver;
  - USB subsystem;
  - BTRFS file system;
  - File sy…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-7088-1</guid>
    </item>
  </channel>
</rss>
