cbcvebase.
CVE-2022-49074
published 2025-02-26

CVE-2022-49074: In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3: Fix GICR_CTLR.RWP polling It turns out that our polling of RWP is totally…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.1th percentile
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3: Fix GICR_CTLR.RWP polling It turns out that our polling of RWP is totally wrong when checking for it in the redistributors, as we test the *distributor* bit index, whereas it is a different bit number in the RDs... Oopsie boo. This is embarassing. Not only because it is wrong, but also because it took *8 years* to notice the blunder... Just fix the damn thing.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 021f653791ad17e03f98aaa7fb933816ae16f161 < c7daf1b4ad809692d5c26f33c02ed8a031066548c7daf1b4ad809692d5c26f33c02ed8a031066548
linuxlinux>= 021f653791ad17e03f98aaa7fb933816ae16f161 < 3c07cc242baf83f0bddbbd9d7945d0bee56d8b573c07cc242baf83f0bddbbd9d7945d0bee56d8b57
linuxlinux>= 021f653791ad17e03f98aaa7fb933816ae16f161 < ff24114bb08d8b90edf2aff0a4fd0689523e6c17ff24114bb08d8b90edf2aff0a4fd0689523e6c17
linuxlinux>= 021f653791ad17e03f98aaa7fb933816ae16f161 < 7218a789abb3e033f5f3a85636ca50d9ae7b0fc97218a789abb3e033f5f3a85636ca50d9ae7b0fc9
linuxlinux>= 021f653791ad17e03f98aaa7fb933816ae16f161 < 60e1eb4811f53f5f60c788297d978515e7a2637a60e1eb4811f53f5f60c788297d978515e7a2637a
linuxlinux>= 021f653791ad17e03f98aaa7fb933816ae16f161 < 6fef3e3179e6ed8fecdd004ede541674ffa7749d6fef3e3179e6ed8fecdd004ede541674ffa7749d
linuxlinux>= 021f653791ad17e03f98aaa7fb933816ae16f161 < 0df6664531a12cdd8fc873f0cac0dcb40243d3e90df6664531a12cdd8fc873f0cac0dcb40243d3e9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 3.17 < 4.19.2384.19.238
linuxlinux_kernel>= 4.20 < 5.4.1895.4.189
linuxlinux_kernel>= 5.11 < 5.15.345.15.34
linuxlinux_kernel>= 5.16 < 5.16.205.16.20
linuxlinux_kernel>= 5.17 < 5.17.35.17.3
linuxlinux_kernel>= 5.5 < 5.10.1115.10.111

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.