CVE-2022-50582
Last modified
CVE-2022-50582 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: regulator: core: Prevent integer underflow By using a ratio of delay to poll_enabled_time that is not integer time_remaining underflows and does not exit the loop as expected. As delay could be derived from DT and poll_enabled_time is defined in the driver this can easily happen. Use a signed iterator to make sure that the loop exits once the remaining time is negative.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: regulator: core: Prevent integer underflow By using a ratio of delay to poll_enabled_time that is not integer time_remaining underflows and does not exit the loop as expected. As delay could be derived from DT and poll_enabled_time is defined in the driver this can easily happen. Use a signed iterator to make sure that the loop exits once the remaining time is negative.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= f7d7ad42a9dc2d63cab6a79fe31e6732a30dacf5, < b051d9bf98bd9cea312b228e264eb6542a9beb67; >= f7d7ad42a9dc2d63cab6a79fe31e6732a30dacf5, < e33da263e9658bfe870ea7836fbbd72f246d7dbd; >= f7d7ad42a9dc2d63cab6a79fe31e6732a30dacf5, < 9f2395316e4845466cb9b5b9b15a171a2c91913c; >= f7d7ad42a9dc2d63cab6a79fe31e6732a30dacf5, < bfe602d9a349360e60e9051c9cafb9fef204524d; >= f7d7ad42a9dc2d63cab6a79fe31e6732a30dacf5, < 8d8e16592022c9650df8aedfe6552ed478d7135b |
| Linux | Linux | 5.9 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50582?
How severe is CVE-2022-50582?
How do I fix CVE-2022-50582?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50576In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50577In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50578In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50579In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50580In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50581In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2022-50583In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50584The Core Config Manager (CCM) in Nagios XI versions prior to…5.4
- CVE-2022-50585The Core Config Manager (CCM) in Nagios XI versions prior to…5.4
- CVE-2022-50586Nagios XI versions prior to 5.8.9 are vulnerable to cross-si…5.4
- CVE-2022-50587Nagios XI versions prior to 5.8.9 are vulnerable to cross-si…5.4
- CVE-2022-50588Nagios XI versions prior to 5.8.9 are vulnerable to cross-si…5.4
Are you affected by CVE-2022-50582?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
