cbcvebase.
CVE-2022-49748
published 2025-03-27

CVE-2022-49748: In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd: fix potential integer overflow on shift of a int The left shift of int 32 bit…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd: fix potential integer overflow on shift of a int The left shift of int 32 bit integer constant 1 is evaluated using 32 bit arithmetic and then passed as a 64 bit function argument. In the case where i is 32 or more this can lead to an overflow. Avoid this by shifting using the BIT_ULL macro instead.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 471af006a747f1c535c8a8c6c0973c320fe01b22 < f84c9b72fb200633774704d8020f769c88a4b249f84c9b72fb200633774704d8020f769c88a4b249
linuxlinux>= 471af006a747f1c535c8a8c6c0973c320fe01b22 < 14cc13e433e1067557435b1adbf05608d7d47a9314cc13e433e1067557435b1adbf05608d7d47a93
linuxlinux>= 471af006a747f1c535c8a8c6c0973c320fe01b22 < a4d01fb87ece45d4164fd725890211ccf9a307a9a4d01fb87ece45d4164fd725890211ccf9a307a9
linuxlinux>= 471af006a747f1c535c8a8c6c0973c320fe01b22 < 08245672cdc6505550d1a5020603b0a8d4a6dcc708245672cdc6505550d1a5020603b0a8d4a6dcc7
linuxlinux>= 5.4.22 < 5.4.2315.4.231
linuxlinux>= 5.5.6 < 5.65.6
linuxlinux>= d8a6a443ff0aea5893f0a7f2726973b496b76420 < fbf7b0e4cef3b5470b610f14fb9faa5ee7f63954fbf7b0e4cef3b5470b610f14fb9faa5ee7f63954
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 5.11 < 5.15.915.15.91
linuxlinux_kernel>= 5.16 < 6.1.96.1.9
linuxlinux_kernel>= 5.4.22 < 5.4.2315.4.231
linuxlinux_kernel>= 5.5.6 < 5.10.1665.10.166

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.