cbcvebase.
CVE-2022-50118
published 2025-06-18

CVE-2022-50118: In the Linux kernel, the following vulnerability has been resolved: powerpc/perf: Optimize clearing the pending PMI and remove WARN_ON for PMI check in…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.5th percentile
In the Linux kernel, the following vulnerability has been resolved: powerpc/perf: Optimize clearing the pending PMI and remove WARN_ON for PMI check in power_pmu_disable commit 2c9ac51b850d ("powerpc/perf: Fix PMU callbacks to clear pending PMI before resetting an overflown PMC") added a new function "pmi_irq_pending" in hw_irq.h. This function is to check if there is a PMI marked as pending in Paca (PACA_IRQ_PMI).This is used in power_pmu_disable in a WARN_ON. The intention here is to provide a warning if there is PMI pending, but no counter is found overflown. During some of the perf runs, below warning is hit: WARNING: CPU: 36 PID: 0 at arch/powerpc/perf/core-book3s.c:1332 power_pmu_disable+0x25c/0x2c0 Modules linked in: NIP [c000000000141c3c] power_pmu_disable+0x25c/0x2c0 LR [c000000000141c8c] power_pmu_disable+0x2ac/0x2c0 Call Trace: [c000000baffcfb90] [c000000000141c8c] power_pmu_disable+0x2ac/0x2c0 (unreliable) [c000000baffcfc10] [c0000000003e2f8c] perf_pmu_disable+0x4c/0x60 [c000000baffcfc30] [c0000000003e3344] group_sched_out.part.124+0x44/0x100 [c000000baffcfc80] [c0000000003e353c] __perf_event_disable+0x13c/0x240 [c000000baffcfcd0] [c0000000003dd334] event_function+0xc4/0x140 [c000000baffcfd20] [c0000000003d855c] remote_function+0x7c/0xa0 [c000000baffcfd50] [c00000000026c394] flush_smp_call_function_queue+0xd4/0x300 [c000000baffcfde0] [c000000000065b24] smp_ipi_demux_relaxed+0xa4/0x100 [c000000baffcfe20] [c0000000000cb2b0] xive_muxed_ipi_action+0x20/0x40 [c000000baffcfe40] [c000000000207c3c] __handle_irq_event_percpu+0x8c/0x250 [c000000baffcfee0] [c000000000207e2c] handle_irq_event_percpu+0x2c/0xa0 [c000000baffcff10] [c000000000210a04] handle_percpu_irq+0x84/0xc0 [c000000baffcff40] [c000000000205f14] generic_handle_irq+0x54/0x80 [c000000baffcff60] [c000000000015740] __do_irq+0x90/0x1d0 [c000000baffcff90] [c000000000016990] __do_IRQ+0xc0/0x140 [c0000009732f3940] [c000000bafceaca8] 0xc000000bafceaca8 [c0000009732f39d0] [c000000000016b78] do_IRQ+0x168/0

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 2c9ac51b850d84ee496b0a5d832ce66d411ae552 < 0a24ea26c3278216642a43291df7976a73a0a7ee0a24ea26c3278216642a43291df7976a73a0a7ee
linuxlinux>= 2c9ac51b850d84ee496b0a5d832ce66d411ae552 < 7e83af3dd4a3afca8f83ffde518cafd52f45b8307e83af3dd4a3afca8f83ffde518cafd52f45b830
linuxlinux>= 2c9ac51b850d84ee496b0a5d832ce66d411ae552 < 890005a7d98f7452cfe86dcfb2aeeb7df01132ce890005a7d98f7452cfe86dcfb2aeeb7df01132ce
linuxlinux>= 5.10.94 < 5.10.1375.10.137
linuxlinux>= 5.15.17 < 5.15.615.15.61
linuxlinux>= 5.16.3 < 5.175.17
linuxlinux>= ef798cd035f316a537fee8ed170c127f12407085 < 875b2bf469d094754ac2ba9af91dcd529eb12bf6875b2bf469d094754ac2ba9af91dcd529eb12bf6
linuxlinux>= fadcafa3959281ce2d96feedece8c75c3f95f8a5 < 87b1a9175f08313f40fcb6d6dc536dbe451090eb87b1a9175f08313f40fcb6d6dc536dbe451090eb
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 5.10.94 < 5.10.1375.10.137
linuxlinux_kernel>= 5.15.17 < 5.15.615.15.61
linuxlinux_kernel>= 5.16.3 < 5.18.185.18.18
linuxlinux_kernel>= 5.19 < 5.19.25.19.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.