CVE-2022-49645
published 2025-02-26CVE-2022-49645: In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Fix shrinker list corruption by madvise IOCTL Calling madvise IOCTL twice on…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/panfrost: Fix shrinker list corruption by madvise IOCTL
Calling madvise IOCTL twice on BO causes memory shrinker list corruption
and crashes kernel because BO is already on the list and it's added to
the list again, while BO should be removed from the list before it's
re-added. Fix it.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.14-1 (bookworm) | linux 5.18.14-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 013b6510131568ce4e01856d5360bfdfe9c3632f < 393594aad55179eb761af41533d8d1d6eb4543b0 | 393594aad55179eb761af41533d8d1d6eb4543b0 |
| linux | linux | >= 013b6510131568ce4e01856d5360bfdfe9c3632f < 0581613df7f9a4c5fac096ce1d5fb15b7b994240 | 0581613df7f9a4c5fac096ce1d5fb15b7b994240 |
| linux | linux | >= 013b6510131568ce4e01856d5360bfdfe9c3632f < 1807d8867402a58b831a7fc16832747ff559a0d1 | 1807d8867402a58b831a7fc16832747ff559a0d1 |
| linux | linux | >= 013b6510131568ce4e01856d5360bfdfe9c3632f < f036392edd9c49090781d8cca26ad6557a63bae4 | f036392edd9c49090781d8cca26ad6557a63bae4 |
| linux | linux | >= 013b6510131568ce4e01856d5360bfdfe9c3632f < 9fc33eaaa979d112d10fea729edcd2a2e21aa912 | 9fc33eaaa979d112d10fea729edcd2a2e21aa912 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.136-1 | 5.10.136-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 5.11 < 5.15.56 | 5.15.56 |
| linux | linux_kernel | >= 5.16 < 5.18.13 | 5.18.13 |
| linux | linux_kernel | >= 5.4 < 5.4.207 | 5.4.207 |
| linux | linux_kernel | >= 5.5 < 5.10.132 | 5.10.132 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p6f8-xrf4-44j4: In the Linux kernel, the following vulnerability has been resolved:
drm/panfrost: Fix shrinker list corruption by madvise IOCTL
Calling madvise IOCT
ghsa_unreviewed·2025-10-23
CVE-2022-49645 [HIGH] CWE-787 GHSA-p6f8-xrf4-44j4: In the Linux kernel, the following vulnerability has been resolved:
drm/panfrost: Fix shrinker list corruption by madvise IOCTL
Calling madvise IOCT
In the Linux kernel, the following vulnerability has been resolved:
drm/panfrost: Fix shrinker list corruption by madvise IOCTL
Calling madvise IOCTL twice on BO causes memory shrinker list corruption
and crashes kernel because BO is already on the list and it's added to
the list again, while BO should be removed from the list before it's
re-added. Fix it.
OSV
CVE-2022-49645: In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Fix shrinker list corruption by madvise IOCTL Calling madvise IOCTL
osv·2025-02-26·CVSS 7.8
CVE-2022-49645 [HIGH] CVE-2022-49645: In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Fix shrinker list corruption by madvise IOCTL Calling madvise IOCTL
In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Fix shrinker list corruption by madvise IOCTL Calling madvise IOCTL twice on BO causes memory shrinker list corruption and crashes kernel because BO is already on the list and it's added to the list again, while BO should be removed from the list before it's re-added. Fix it.
Red Hat
kernel: drm/panfrost: Fix shrinker list corruption by madvise IOCTL
vendor_redhat·2025-02-26·CVSS 7.8
CVE-2022-49645 [HIGH] kernel: drm/panfrost: Fix shrinker list corruption by madvise IOCTL
kernel: drm/panfrost: Fix shrinker list corruption by madvise IOCTL
In the Linux kernel, the following vulnerability has been resolved:
drm/panfrost: Fix shrinker list corruption by madvise IOCTL
Calling madvise IOCTL twice on BO causes memory shrinker list corruption
and crashes kernel because BO is already on the list and it's added to
the list again, while BO should be removed from the list before it's
re-added. Fix it.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2022-49645: linux - In the Linux kernel, the following vulnerability has been resolved: drm/panfros...
vendor_debian·2022·CVSS 7.8
CVE-2022-49645 [HIGH] CVE-2022-49645: linux - In the Linux kernel, the following vulnerability has been resolved: drm/panfros...
In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Fix shrinker list corruption by madvise IOCTL Calling madvise IOCTL twice on BO causes memory shrinker list corruption and crashes kernel because BO is already on the list and it's added to the list again, while BO should be removed from the list before it's re-added. Fix it.
Scope: local
bookworm: resolved (fixed in 5.18.14-1)
bullseye: resolved (fixed in 5.10.136-1)
forky: resolved (fixed in 5.18.14-1)
sid: resolved (fixed in 5.18.14-1)
trixie: resolved (fixed in 5.18.14-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0581613df7f9a4c5fac096ce1d5fb15b7b994240https://git.kernel.org/stable/c/1807d8867402a58b831a7fc16832747ff559a0d1https://git.kernel.org/stable/c/393594aad55179eb761af41533d8d1d6eb4543b0https://git.kernel.org/stable/c/9fc33eaaa979d112d10fea729edcd2a2e21aa912https://git.kernel.org/stable/c/f036392edd9c49090781d8cca26ad6557a63bae4
2025-02-26
Published