CVE-2022-50575

UnknownEPSS 0.20%

Last modified

CVE-2022-50575 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource() As 'kdata.num' is user-controlled data, if user tries to allocate memory larger than(>=) MAX_ORDER, then kcalloc() will fail, it creates a stack trace and messes up dmesg with a warning. Call trace: -> privcmd_ioctl --> privcmd_ioctl_mmap_resource Add __GFP_NOWARN in order to avoid too large allocation warning. This is detected by static analysis using smatch.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource() As 'kdata.num' is user-controlled data, if user tries to allocate memory larger than(>=) MAX_ORDER, then kcalloc() will fail, it creates a stack trace and messes up dmesg with a warning. Call trace: -> privcmd_ioctl --> privcmd_ioctl_mmap_resource Add __GFP_NOWARN in order to avoid too large allocation warning. This is detected by static analysis using smatch.

Metrics

EPSS Probability
0.20%

10.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 3ad0876554cafa368f574d4d408468510543e9ff, < 5d68ae32d132ea2af73bc223fd64c46f85302a8b; >= 3ad0876554cafa368f574d4d408468510543e9ff, < 4f983ee5e5de924d93a7bbb4e6f68f38c6256cd5; >= 3ad0876554cafa368f574d4d408468510543e9ff, < 46026bb057c35f5bb111bf95e00cd8366d2e34d4; >= 3ad0876554cafa368f574d4d408468510543e9ff, < 0bf874183b32eae2cc20e3c5be38ec3d33e7e564; >= 3ad0876554cafa368f574d4d408468510543e9ff, < e0c5f1058ed96f2b7487560c4c4cbd768d13d065; >= 3ad0876554cafa368f574d4d408468510543e9ff, < 4da411086f5ab32f811a89ef804980ec106ebb65; >= 3ad0876554cafa368f574d4d408468510543e9ff, < 8b997b2bb2c53b76a6db6c195930e9ab8e4b0c79
LinuxLinux4.18

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2022-50575?
In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource() As 'kdata.num' is user-controlled data, if user tries to allocate memory larger than(>=) MAX_ORDER, then kcalloc() will fail, it creates a stack trace and messes up dmesg with a warning. Call trace: -> privcmd_ioctl --> privcmd_ioctl_mmap_resource Add __GFP_NOWARN in order to avoid too large allocation warning. This is detected by static analysis using smatch.
How severe is CVE-2022-50575?
Severity scoring for CVE-2022-50575 is pending analysis. The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2022-50575?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2022

Are you affected by CVE-2022-50575?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST