cbcvebase.
CVE-2022-49645
published 2025-02-26

CVE-2022-49645: In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Fix shrinker list corruption by madvise IOCTL Calling madvise IOCTL twice on…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.0th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Fix shrinker list corruption by madvise IOCTL Calling madvise IOCTL twice on BO causes memory shrinker list corruption and crashes kernel because BO is already on the list and it's added to the list again, while BO should be removed from the list before it's re-added. Fix it.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= 013b6510131568ce4e01856d5360bfdfe9c3632f < 393594aad55179eb761af41533d8d1d6eb4543b0393594aad55179eb761af41533d8d1d6eb4543b0
linuxlinux>= 013b6510131568ce4e01856d5360bfdfe9c3632f < 0581613df7f9a4c5fac096ce1d5fb15b7b9942400581613df7f9a4c5fac096ce1d5fb15b7b994240
linuxlinux>= 013b6510131568ce4e01856d5360bfdfe9c3632f < 1807d8867402a58b831a7fc16832747ff559a0d11807d8867402a58b831a7fc16832747ff559a0d1
linuxlinux>= 013b6510131568ce4e01856d5360bfdfe9c3632f < f036392edd9c49090781d8cca26ad6557a63bae4f036392edd9c49090781d8cca26ad6557a63bae4
linuxlinux>= 013b6510131568ce4e01856d5360bfdfe9c3632f < 9fc33eaaa979d112d10fea729edcd2a2e21aa9129fc33eaaa979d112d10fea729edcd2a2e21aa912
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.136-15.10.136-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 5.11 < 5.15.565.15.56
linuxlinux_kernel>= 5.16 < 5.18.135.18.13
linuxlinux_kernel>= 5.4 < 5.4.2075.4.207
linuxlinux_kernel>= 5.5 < 5.10.1325.10.132

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.