Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: powercap: intel_rapl: fix UBSAN shift-out-of-bounds issue When value < time_unit, the parameter of ilog2() will be zero and the return value is -1. u64(-1) is too large for shift exponent and then will trigger shift-out-of-bounds: shift exponent 18446744073709551615 is too large for 32-bit type 'int' Call Trace: rapl_compute_time_window_core rapl_write_data_raw set_time_window store_constraint_time_window_us
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 4.9.331 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/139bbbd01114433b80fe59f5e1330615aadf9752Patch
- https://git.kernel.org/stable/c/1d94af37565e4d3c26b0d63428e093a37d5b4c32Patch
- https://git.kernel.org/stable/c/2d93540014387d1c73b9ccc4d7895320df66d01bPatch
- https://git.kernel.org/stable/c/3eb0ba70376f6ee40fa843fc9cee49269370b0b3Patch
- https://git.kernel.org/stable/c/42f79dbb9514f726ff21df25f09cb0693b0b2445Patch
- https://git.kernel.org/stable/c/49a6ffdaed60f0eb52c198fafebc05994e16e305Patch
- https://git.kernel.org/stable/c/4ebba43384722adbd325baec3a12c572d94488ebPatch
- https://git.kernel.org/stable/c/6216b685b8f48ab7b721a6fd5acbf526b41c13e8Patch
- https://git.kernel.org/stable/c/708b9abe1b4a2f050a483db4b7edfc446b13df1fPatch
FAQ
What is CVE-2022-50366?
CVE-2022-50366 is a vulnerability with a CVSS score of 7.1 (HIGH). In the Linux kernel, the following vulnerability has been resolved: powercap: intel_rapl: fix UBSAN shift-out-of-bounds issue When value < time_unit, the parameter of ilog2() will be zero and the re...
How severe is CVE-2022-50366?
CVE-2022-50366 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-50366?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.