cbcvebase.
CVE-2022-49175
published 2025-02-26

CVE-2022-49175: In the Linux kernel, the following vulnerability has been resolved: PM: core: keep irq flags in device_pm_check_callbacks() The function…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
19.0th percentile
In the Linux kernel, the following vulnerability has been resolved: PM: core: keep irq flags in device_pm_check_callbacks() The function device_pm_check_callbacks() can be called under the spin lock (in the reported case it happens from genpd_add_device() -> dev_pm_domain_set(), when the genpd uses spinlocks rather than mutexes. However this function uncoditionally uses spin_lock_irq() / spin_unlock_irq(), thus not preserving the CPU flags. Use the irqsave/irqrestore instead. The backtrace for the reference: [ 2.752010] ------------[ cut here ]------------ [ 2.756769] raw_local_irq_restore() called with IRQs enabled [ 2.762596] WARNING: CPU: 4 PID: 1 at kernel/locking/irqflag-debug.c:10 warn_bogus_irq_restore+0x34/0x50 [ 2.772338] Modules linked in: [ 2.775487] CPU: 4 PID: 1 Comm: swapper/0 Tainted: G S 5.17.0-rc6-00384-ge330d0d82eff-dirty #684 [ 2.781384] Freeing initrd memory: 46024K [ 2.785839] pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 2.785841] pc : warn_bogus_irq_restore+0x34/0x50 [ 2.785844] lr : warn_bogus_irq_restore+0x34/0x50 [ 2.785846] sp : ffff80000805b7d0 [ 2.785847] x29: ffff80000805b7d0 x28: 0000000000000000 x27: 0000000000000002 [ 2.785850] x26: ffffd40e80930b18 x25: ffff7ee2329192b8 x24: ffff7edfc9f60800 [ 2.785853] x23: ffffd40e80930b18 x22: ffffd40e80930d30 x21: ffff7edfc0dffa00 [ 2.785856] x20: ffff7edfc09e3768 x19: 0000000000000000 x18: ffffffffffffffff [ 2.845775] x17: 6572206f74206465 x16: 6c696166203a3030 x15: ffff80008805b4f7 [ 2.853108] x14: 0000000000000000 x13: ffffd40e809550b0 x12: 00000000000003d8 [ 2.860441] x11: 0000000000000148 x10: ffffd40e809550b0 x9 : ffffd40e809550b0 [ 2.867774] x8 : 00000000ffffefff x7 : ffffd40e809ad0b0 x6 : ffffd40e809ad0b0 [ 2.875107] x5 : 000000000000bff4 x4 : 0000000000000000 x3 : 0000000000000000 [ 2.882440] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff7edfc03a8000 [ 2.889774] Call trace: [ 2.892290] warn_bogus_irq_restore+0x34/0x50 [ 2.896770] _raw_spin_unlock_irqrestor

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= aa8e54b559479d0cb7eb632ba443b8cacd20cd4b < 3ec80d52b9b74b9e691997632a543c73eddfeba03ec80d52b9b74b9e691997632a543c73eddfeba0
linuxlinux>= aa8e54b559479d0cb7eb632ba443b8cacd20cd4b < 78c4d68b952f5f537788dbd454031ea9bf50f64278c4d68b952f5f537788dbd454031ea9bf50f642
linuxlinux>= aa8e54b559479d0cb7eb632ba443b8cacd20cd4b < be8bc05f38d667eda1e820bc6f69234795be7809be8bc05f38d667eda1e820bc6f69234795be7809
linuxlinux>= aa8e54b559479d0cb7eb632ba443b8cacd20cd4b < 0cccf9d4fb45f1acbc0bbf6d7e4d8d0fb7a104160cccf9d4fb45f1acbc0bbf6d7e4d8d0fb7a10416
linuxlinux>= aa8e54b559479d0cb7eb632ba443b8cacd20cd4b < ede1ef1a7de973321699736ef96d01a4b9a6fe9eede1ef1a7de973321699736ef96d01a4b9a6fe9e
linuxlinux>= aa8e54b559479d0cb7eb632ba443b8cacd20cd4b < c29642ba72f87c0a3d7449f7db5d6d76a7ed53c3c29642ba72f87c0a3d7449f7db5d6d76a7ed53c3
linuxlinux>= aa8e54b559479d0cb7eb632ba443b8cacd20cd4b < 2add538e57a2825c61d639260386f385c75e41662add538e57a2825c61d639260386f385c75e4166
linuxlinux>= aa8e54b559479d0cb7eb632ba443b8cacd20cd4b < c7c0ec5a1dcc3eaa1e85c804c2ccf46e457788a3c7c0ec5a1dcc3eaa1e85c804c2ccf46e457788a3
linuxlinux>= aa8e54b559479d0cb7eb632ba443b8cacd20cd4b < 524bb1da785a7ae43dd413cd392b5071c6c367f8524bb1da785a7ae43dd413cd392b5071c6c367f8
linuxlinux_kernel< 4.9.3114.9.311
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 4.10 < 4.14.2764.14.276
linuxlinux_kernel>= 4.15 < 4.19.2384.19.238
linuxlinux_kernel>= 4.20 < 5.4.1895.4.189
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.5 < 5.10.1105.10.110

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.