cbcvebase.
CVE-2022-49189
published 2025-02-26

CVE-2022-49189: In the Linux kernel, the following vulnerability has been resolved: clk: qcom: clk-rcg2: Update logic to calculate D value for RCG The display pixel clock has…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
18.2th percentile
In the Linux kernel, the following vulnerability has been resolved: clk: qcom: clk-rcg2: Update logic to calculate D value for RCG The display pixel clock has a requirement on certain newer platforms to support M/N as (2/3) and the final D value calculated results in underflow errors. As the current implementation does not check for D value is within the accepted range for a given M & N value. Update the logic to calculate the final D value based on the range.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxlinux
linuxlinux>= 99cbd064b059f222c8839ba433a68b2d6ee33066 < 52592f9afbfe01bce8f8953e4f19cbe3bcbdbd3a52592f9afbfe01bce8f8953e4f19cbe3bcbdbd3a
linuxlinux>= 99cbd064b059f222c8839ba433a68b2d6ee33066 < 334720f418f57b1d969dad2117b21f9388cb9395334720f418f57b1d969dad2117b21f9388cb9395
linuxlinux>= 99cbd064b059f222c8839ba433a68b2d6ee33066 < 34dca60982e93e69ae442aa2d36ce61c9a3bb56334dca60982e93e69ae442aa2d36ce61c9a3bb563
linuxlinux>= 99cbd064b059f222c8839ba433a68b2d6ee33066 < 96888f0dcf351e758b9df57e015a48427ca709c196888f0dcf351e758b9df57e015a48427ca709c1
linuxlinux>= 99cbd064b059f222c8839ba433a68b2d6ee33066 < a4e2e31971354790b0d1fa3e783452a9d135fcffa4e2e31971354790b0d1fa3e783452a9d135fcff
linuxlinux>= 99cbd064b059f222c8839ba433a68b2d6ee33066 < 58922910add18583d5273c2edcdb9fd7bf4eca0258922910add18583d5273c2edcdb9fd7bf4eca02
linuxlinux_kernel>= 0 < 5.10.113-15.10.113-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 3.16 < 5.4.1895.4.189
linuxlinux_kernel>= 5.11 < 5.15.335.15.33
linuxlinux_kernel>= 5.16 < 5.16.195.16.19
linuxlinux_kernel>= 5.17 < 5.17.25.17.2
linuxlinux_kernel>= 5.5 < 5.10.1105.10.110

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.