cbcvebase.
CVE-2022-49387
published 2025-02-26

CVE-2022-49387: In the Linux kernel, the following vulnerability has been resolved: watchdog: rzg2l_wdt: Fix 32bit overflow issue The value of timer_cycle_us can be 0 due to…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.7th percentile
In the Linux kernel, the following vulnerability has been resolved: watchdog: rzg2l_wdt: Fix 32bit overflow issue The value of timer_cycle_us can be 0 due to 32bit overflow. For eg:- If we assign the counter value "0xfff" for computing maxval. This patch fixes this issue by appending ULL to 1024, so that it is promoted to 64bit. This patch also fixes the warning message, 'watchdog: Invalid min and max timeout values, resetting to 0!'.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 2cbc5cd0b55fa2310cc557c77b0665f5e00272de < e07b9fa0dc32b492de85528caaf9f0c605d8424fe07b9fa0dc32b492de85528caaf9f0c605d8424f
linuxlinux>= 2cbc5cd0b55fa2310cc557c77b0665f5e00272de < b95a47667d34e76c2c9013f8e3b1e5039a5a0b76b95a47667d34e76c2c9013f8e3b1e5039a5a0b76
linuxlinux>= 2cbc5cd0b55fa2310cc557c77b0665f5e00272de < ea2949df22a533cdf75e4583c00b1ce94cd5a83bea2949df22a533cdf75e4583c00b1ce94cd5a83b
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 5.17 < 5.17.155.17.15
linuxlinux_kernel>= 5.18 < 5.18.45.18.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.