CVE-2022-49145
published 2025-02-26CVE-2022-49145: In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Avoid out of bounds access when parsing _CPC data If the NumEntries field in…
PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.28%
19.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
ACPI: CPPC: Avoid out of bounds access when parsing _CPC data
If the NumEntries field in the _CPC return package is less than 2, do
not attempt to access the "Revision" element of that package, because
it may not be present then.
BugLink: https://lore.kernel.org/lkml/20220322143534.GC32582@xsang-OptiPlex-9020/
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.17.3-1 (bookworm) | linux 5.17.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 337aadff8e4567e39669e07d9a88b789d78458b5 < b3f15609ffa521de12244cd6af24002030dda3f5 | b3f15609ffa521de12244cd6af24002030dda3f5 |
| linux | linux | >= 337aadff8e4567e39669e07d9a88b789d78458b5 < d208ea44e25b31db5a4d5e8c31df51787a3e9303 | d208ea44e25b31db5a4d5e8c31df51787a3e9303 |
| linux | linux | >= 337aadff8e4567e39669e07d9a88b789d78458b5 < 28d5387c1994f5e1e0d41b30a1f3dd6e1f609252 | 28d5387c1994f5e1e0d41b30a1f3dd6e1f609252 |
| linux | linux | >= 337aadff8e4567e39669e07d9a88b789d78458b5 < cb249f8c00f40dba83b7da8207ac14ca46e9ec9e | cb249f8c00f40dba83b7da8207ac14ca46e9ec9e |
| linux | linux | >= 337aadff8e4567e39669e07d9a88b789d78458b5 < e5b681822cac1f8093759b02e16c06b2c64b6788 | e5b681822cac1f8093759b02e16c06b2c64b6788 |
| linux | linux | >= 337aadff8e4567e39669e07d9a88b789d78458b5 < 97b5593fd1b182b3fdb180b6bbe64ec09669988b | 97b5593fd1b182b3fdb180b6bbe64ec09669988b |
| linux | linux | >= 337aadff8e4567e39669e07d9a88b789d78458b5 < b80b19b32a432c9eee1cd200ef7aaddf608f54d1 | b80b19b32a432c9eee1cd200ef7aaddf608f54d1 |
| linux | linux | >= 337aadff8e4567e39669e07d9a88b789d78458b5 < d7339f2a3938fb56b5f28d53f5345900b5fa0e74 | d7339f2a3938fb56b5f28d53f5345900b5fa0e74 |
| linux | linux | >= 337aadff8e4567e39669e07d9a88b789d78458b5 < 40d8abf364bcab23bc715a9221a3c8623956257b | 40d8abf364bcab23bc715a9221a3c8623956257b |
| linux | linux_kernel | >= 0 < 5.10.113-1 | 5.10.113-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 4.10 < 4.14.276 | 4.14.276 |
| linux | linux_kernel | >= 4.15 < 4.19.238 | 4.19.238 |
| linux | linux_kernel | >= 4.20 < 5.4.189 | 5.4.189 |
| linux | linux_kernel | >= 4.4 < 4.9.311 | 4.9.311 |
| linux | linux_kernel | >= 5.11 < 5.15.33 | 5.15.33 |
| linux | linux_kernel | >= 5.16 < 5.16.19 | 5.16.19 |
| linux | linux_kernel | >= 5.17 < 5.17.2 | 5.17.2 |
| linux | linux_kernel | >= 5.5 < 5.10.110 | 5.10.110 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j4x2-v364-5ppc: In the Linux kernel, the following vulnerability has been resolved:
ACPI: CPPC: Avoid out of bounds access when parsing _CPC data
If the NumEntries
ghsa_unreviewed·2025-09-23
CVE-2022-49145 [HIGH] CWE-125 GHSA-j4x2-v364-5ppc: In the Linux kernel, the following vulnerability has been resolved:
ACPI: CPPC: Avoid out of bounds access when parsing _CPC data
If the NumEntries
In the Linux kernel, the following vulnerability has been resolved:
ACPI: CPPC: Avoid out of bounds access when parsing _CPC data
If the NumEntries field in the _CPC return package is less than 2, do
not attempt to access the "Revision" element of that package, because
it may not be present then.
BugLink: https://lore.kernel.org/lkml/20220322143534.GC32582@xsang-OptiPlex-9020/
OSV
CVE-2022-49145: In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Avoid out of bounds access when parsing _CPC data If the NumEntries fi
osv·2025-02-26·CVSS 7.1
CVE-2022-49145 [HIGH] CVE-2022-49145: In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Avoid out of bounds access when parsing _CPC data If the NumEntries fi
In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Avoid out of bounds access when parsing _CPC data If the NumEntries field in the _CPC return package is less than 2, do not attempt to access the "Revision" element of that package, because it may not be present then. BugLink: https://lore.kernel.org/lkml/20220322143534.GC32582@xsang-OptiPlex-9020/
Red Hat
kernel: ACPI: CPPC: Avoid out of bounds access when parsing _CPC data
vendor_redhat·2025-02-26·CVSS 7.1
CVE-2022-49145 [HIGH] kernel: ACPI: CPPC: Avoid out of bounds access when parsing _CPC data
kernel: ACPI: CPPC: Avoid out of bounds access when parsing _CPC data
In the Linux kernel, the following vulnerability has been resolved:
ACPI: CPPC: Avoid out of bounds access when parsing _CPC data
If the NumEntries field in the _CPC return package is less than 2, do
not attempt to access the "Revision" element of that package, because
it may not be present then.
BugLink: https://lore.kernel.org/lkml/20220322143534.GC32582@xsang-OptiPlex-9020/
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 8) - Affected
Package: kernel-rt (Red
Debian
CVE-2022-49145: linux - In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC:...
vendor_debian·2022·CVSS 7.1
CVE-2022-49145 [HIGH] CVE-2022-49145: linux - In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC:...
In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Avoid out of bounds access when parsing _CPC data If the NumEntries field in the _CPC return package is less than 2, do not attempt to access the "Revision" element of that package, because it may not be present then. BugLink: https://lore.kernel.org/lkml/20220322143534.GC32582@xsang-OptiPlex-9020/
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.17.3-1)
sid: resolved (fixed in 5.17.3-1)
trixie: resolved (fixed in 5.17.3-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/28d5387c1994f5e1e0d41b30a1f3dd6e1f609252https://git.kernel.org/stable/c/40d8abf364bcab23bc715a9221a3c8623956257bhttps://git.kernel.org/stable/c/97b5593fd1b182b3fdb180b6bbe64ec09669988bhttps://git.kernel.org/stable/c/b3f15609ffa521de12244cd6af24002030dda3f5https://git.kernel.org/stable/c/b80b19b32a432c9eee1cd200ef7aaddf608f54d1https://git.kernel.org/stable/c/cb249f8c00f40dba83b7da8207ac14ca46e9ec9ehttps://git.kernel.org/stable/c/d208ea44e25b31db5a4d5e8c31df51787a3e9303https://git.kernel.org/stable/c/d7339f2a3938fb56b5f28d53f5345900b5fa0e74https://git.kernel.org/stable/c/e5b681822cac1f8093759b02e16c06b2c64b6788
2025-02-26
Published