cbcvebase.
CVE-2022-49650
published 2025-02-26

CVE-2022-49650: In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: bam_dma: fix runtime PM underflow Commit dbad41e7bb5f ("dmaengine: qcom…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.26%
17.6th percentile
In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: bam_dma: fix runtime PM underflow Commit dbad41e7bb5f ("dmaengine: qcom: bam_dma: check if the runtime pm enabled") caused unbalanced pm_runtime_get/put() calls when the bam is controlled remotely. This commit reverts it and just enables pm_runtime in all cases, the clk_* functions already just nop when the clock is NULL. Also clean up a bit by removing unnecessary bamclk null checks.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= dbad41e7bb5f4b9949ff5ea1d76c20711f326308 < 2f6ded79068cac8cff41d5d5632564165d98ee122f6ded79068cac8cff41d5d5632564165d98ee12
linuxlinux>= dbad41e7bb5f4b9949ff5ea1d76c20711f326308 < b702a1077b51fcb39507cc3bd39206f539319a96b702a1077b51fcb39507cc3bd39206f539319a96
linuxlinux>= dbad41e7bb5f4b9949ff5ea1d76c20711f326308 < 0ac9c3dd0d6fe293cd5044cfad10bec27d171e4e0ac9c3dd0d6fe293cd5044cfad10bec27d171e4e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 4.17.1 < 5.15.545.15.54
linuxlinux_kernel>= 5.16 < 5.18.115.18.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.