cbcvebase.
CVE-2022-49034
published 2024-12-27

CVE-2022-49034: In the Linux kernel, the following vulnerability has been resolved: sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK When CONFIG_CPUMASK_OFFSTACK and…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved: sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates a runtime warning similar as below when showing /proc/cpuinfo. Fix this by using nr_cpu_ids (the runtime limit) instead of NR_CPUS to iterate CPUs. [ 3.052463] ------------[ cut here ]------------ [ 3.059679] WARNING: CPU: 3 PID: 1 at include/linux/cpumask.h:108 show_cpuinfo+0x5e8/0x5f0 [ 3.070072] Modules linked in: efivarfs autofs4 [ 3.076257] CPU: 0 PID: 1 Comm: systemd Not tainted 5.19-rc5+ #1052 [ 3.099465] Stack : 9000000100157b08 9000000000f18530 9000000000cf846c 9000000100154000 [ 3.109127] 9000000100157a50 0000000000000000 9000000100157a58 9000000000ef7430 [ 3.118774] 90000001001578e8 0000000000000040 0000000000000020 ffffffffffffffff [ 3.128412] 0000000000aaaaaa 1ab25f00eec96a37 900000010021de80 900000000101c890 [ 3.138056] 0000000000000000 0000000000000000 0000000000000000 0000000000aaaaaa [ 3.147711] ffff8000339dc220 0000000000000001 0000000006ab4000 0000000000000000 [ 3.157364] 900000000101c998 0000000000000004 9000000000ef7430 0000000000000000 [ 3.167012] 0000000000000009 000000000000006c 0000000000000000 0000000000000000 [ 3.176641] 9000000000d3de08 9000000001639390 90000000002086d8 00007ffff0080286 [ 3.186260] 00000000000000b0 0000000000000004 0000000000000000 0000000000071c1c [ 3.195868] ... [ 3.199917] Call Trace: [ 3.203941] [] show_stack+0x38/0x14c [ 3.210666] [] dump_stack_lvl+0x60/0x88 [ 3.217625] [] __warn+0xd0/0x100 [ 3.223958] [] warn_slowpath_fmt+0x7c/0xcc [ 3.231150] [] show_cpuinfo+0x5e8/0x5f0 [ 3.238080] [] seq_read_iter+0x354/0x4b4 [ 3.245098] [] new_sync_read+0x17c/0x1c4 [ 3.252114] [] vfs_read+0x138/0x1d0 [ 3.258694] [] ksys_read+0x70/0x100 [ 3.265265] [] do_syscall+0x7c/0x94 [ 3.271820] [] handle_syscall+0xc4/0x160 [ 3.281824] ---[ end trace 8b484262b4b8c24c ]---

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8fbb57eabfc8ae67115cb47f904614c99d626a898fbb57eabfc8ae67115cb47f904614c99d626a89
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f8f26cf69003a37ffa947631fc0e6fe6daee624af8f26cf69003a37ffa947631fc0e6fe6daee624a
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 77755dc95ff2f9a3e473acc1e039f498629949ea77755dc95ff2f9a3e473acc1e039f498629949ea
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e2b91997db286a5dd3cca6d5d9c20004851f22ebe2b91997db286a5dd3cca6d5d9c20004851f22eb
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2b6b8e011fab680a223b5e07a3c64774156ec6fe2b6b8e011fab680a223b5e07a3c64774156ec6fe
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 09faf32c682ea4a547200b8b9e04d8b3c8e84b5509faf32c682ea4a547200b8b9e04d8b3c8e84b55
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 39373f6f89f52770a5405d30dddd08a27d09787239373f6f89f52770a5405d30dddd08a27d097872
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 701e32900683378d93693fec15d133e2c5f7ada2701e32900683378d93693fec15d133e2c5f7ada2
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3c891f7c6a4e90bb1199497552f24b26e46383bc3c891f7c6a4e90bb1199497552f24b26e46383bc
linuxlinux_kernel< 4.19.3254.19.325
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.20 < 5.4.2875.4.287
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 5.5 < 5.10.2315.10.231
linuxlinux_kernel>= 6.12 < 6.12.26.12.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.