CVE-2022-50580
Last modified
CVE-2022-50580 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: blk-throttle: prevent overflow while calculating wait time There is a problem found by code review in tg_with_in_bps_limit() that 'bps_limit * jiffy_elapsed_rnd' might overflow. Fix the problem by calling mul_u64_u64_div_u64() instead.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: blk-throttle: prevent overflow while calculating wait time There is a problem found by code review in tg_with_in_bps_limit() that 'bps_limit * jiffy_elapsed_rnd' might overflow. Fix the problem by calling mul_u64_u64_div_u64() instead.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= e43473b7f223ec866f7db273697e76c337c390f9, < 19c010ae44f0ce52b5436080492a61a092ee0cf4; >= e43473b7f223ec866f7db273697e76c337c390f9, < 70b2adb1d698fbc63d3b3848c452524dc15872c5; >= e43473b7f223ec866f7db273697e76c337c390f9, < cc6f0855bf8d9b729df28ff443ced7350c380dbd; >= e43473b7f223ec866f7db273697e76c337c390f9, < ca67b0563b39e79290c23e509319c178b9ca9104; >= e43473b7f223ec866f7db273697e76c337c390f9, < 8d6bbaada2e0a65f9012ac4c2506460160e7237a |
| Linux | Linux | 2.6.37 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50580?
How severe is CVE-2022-50580?
How do I fix CVE-2022-50580?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50574In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50575In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50576In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50577In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50578In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50579In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50581In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50582In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50583In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50584The Core Config Manager (CCM) in Nagios XI versions prior to…5.4
- CVE-2022-50585The Core Config Manager (CCM) in Nagios XI versions prior to…5.4
- CVE-2022-50586Nagios XI versions prior to 5.8.9 are vulnerable to cross-si…5.4
Are you affected by CVE-2022-50580?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
