cbcvebase.
CVE-2022-49749
published 2025-03-27

CVE-2022-49749: In the Linux kernel, the following vulnerability has been resolved: i2c: designware: use casting of u64 in clock multiplication to avoid overflow In functions…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved: i2c: designware: use casting of u64 in clock multiplication to avoid overflow In functions i2c_dw_scl_lcnt() and i2c_dw_scl_hcnt() may have overflow by depending on the values of the given parameters including the ic_clk. For example in our use case where ic_clk is larger than one million, multiplication of ic_clk * 4700 will result in 32 bit overflow. Add cast of u64 to the calculation to avoid multiplication overflow, and use the corresponding define for divide.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux
linuxlinux>= 2373f6b9744d5373b886f3ce1a985193cca0a356 < ed173f77fd28a3e4fffc13b3f28687b9eba61157ed173f77fd28a3e4fffc13b3f28687b9eba61157
linuxlinux>= 2373f6b9744d5373b886f3ce1a985193cca0a356 < 2f29d780bd691d20e89e5b35d5e6568607115e942f29d780bd691d20e89e5b35d5e6568607115e94
linuxlinux>= 2373f6b9744d5373b886f3ce1a985193cca0a356 < 9f36aae9e80e79b7a6d62227eaa96935166be9fe9f36aae9e80e79b7a6d62227eaa96935166be9fe
linuxlinux>= 2373f6b9744d5373b886f3ce1a985193cca0a356 < c8c37bc514514999e62a17e95160ed9ebf75ca8dc8c37bc514514999e62a17e95160ed9ebf75ca8d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 3.2 < 5.10.1665.10.166
linuxlinux_kernel>= 5.11 < 5.15.915.15.91
linuxlinux_kernel>= 5.16 < 6.1.96.1.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.