CVE-2022-50330
published 2025-09-15CVE-2022-50330: In the Linux kernel, the following vulnerability has been resolved: crypto: cavium - prevent integer overflow loading firmware The "code_length" value comes…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
crypto: cavium - prevent integer overflow loading firmware
The "code_length" value comes from the firmware file. If your firmware
is untrusted realistically there is probably very little you can do to
protect yourself. Still we try to limit the damage as much as possible.
Also Smatch marks any data read from the filesystem as untrusted and
prints warnings if it not capped correctly.
The "ntohl(ucode->code_length) * 2" multiplication can have an
integer overflow.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.3-1 (bookworm) | linux 6.0.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 9e2c7d99941d000a36f68a3594cec27a1bbea274 < c4d4c2afd08dfb3cd1c880d1811ede2568e81a6d | c4d4c2afd08dfb3cd1c880d1811ede2568e81a6d |
| linux | linux | >= 9e2c7d99941d000a36f68a3594cec27a1bbea274 < 90e483e7f20c32287d2a9da967e122938f52737a | 90e483e7f20c32287d2a9da967e122938f52737a |
| linux | linux | >= 9e2c7d99941d000a36f68a3594cec27a1bbea274 < 584561e94260268abe1c83e00d9c205565cb7bc5 | 584561e94260268abe1c83e00d9c205565cb7bc5 |
| linux | linux | >= 9e2c7d99941d000a36f68a3594cec27a1bbea274 < 3a720eb89026c5241b8c4abb33370dc6fb565eee | 3a720eb89026c5241b8c4abb33370dc6fb565eee |
| linux | linux | >= 9e2c7d99941d000a36f68a3594cec27a1bbea274 < 172c8a24fc8312cf6b88d3c88469653fdcb1c127 | 172c8a24fc8312cf6b88d3c88469653fdcb1c127 |
| linux | linux | >= 9e2c7d99941d000a36f68a3594cec27a1bbea274 < 371fa5129af53a79f6dddc90fe5bb0825cbe72a4 | 371fa5129af53a79f6dddc90fe5bb0825cbe72a4 |
| linux | linux | >= 9e2c7d99941d000a36f68a3594cec27a1bbea274 < e29fd7a6852376d2cfb95ad5d6d3eeff93f815e9 | e29fd7a6852376d2cfb95ad5d6d3eeff93f815e9 |
| linux | linux | >= 9e2c7d99941d000a36f68a3594cec27a1bbea274 < 2526d6bf27d15054bb0778b2f7bc6625fd934905 | 2526d6bf27d15054bb0778b2f7bc6625fd934905 |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 4.11 < 4.14.296 | 4.14.296 |
| linux | linux_kernel | >= 4.15 < 4.19.262 | 4.19.262 |
| linux | linux_kernel | >= 4.20 < 5.4.220 | 5.4.220 |
| linux | linux_kernel | >= 5.11 < 5.15.75 | 5.15.75 |
| linux | linux_kernel | >= 5.16 < 5.19.17 | 5.19.17 |
| linux | linux_kernel | >= 5.5 < 5.10.150 | 5.10.150 |
| linux | linux_kernel | >= 6.0 < 6.0.3 | 6.0.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w6rv-q4xv-mrf3: In the Linux kernel, the following vulnerability has been resolved:
crypto: cavium - prevent integer overflow loading firmware
The "code_length" val
ghsa_unreviewed·2025-09-15
CVE-2022-50330 [MEDIUM] CWE-190 GHSA-w6rv-q4xv-mrf3: In the Linux kernel, the following vulnerability has been resolved:
crypto: cavium - prevent integer overflow loading firmware
The "code_length" val
In the Linux kernel, the following vulnerability has been resolved:
crypto: cavium - prevent integer overflow loading firmware
The "code_length" value comes from the firmware file. If your firmware
is untrusted realistically there is probably very little you can do to
protect yourself. Still we try to limit the damage as much as possible.
Also Smatch marks any data read from the filesystem as untrusted and
prints warnings if it not capped correctly.
The "ntohl(ucode->code_length) * 2" multiplication can have an
integer overflow.
OSV
CVE-2022-50330: In the Linux kernel, the following vulnerability has been resolved: crypto: cavium - prevent integer overflow loading firmware The "code_length" value
osv·2025-09-15·CVSS 5.5
CVE-2022-50330 [MEDIUM] CVE-2022-50330: In the Linux kernel, the following vulnerability has been resolved: crypto: cavium - prevent integer overflow loading firmware The "code_length" value
In the Linux kernel, the following vulnerability has been resolved: crypto: cavium - prevent integer overflow loading firmware The "code_length" value comes from the firmware file. If your firmware is untrusted realistically there is probably very little you can do to protect yourself. Still we try to limit the damage as much as possible. Also Smatch marks any data read from the filesystem as untrusted and prints warnings if it not capped correctly. The "ntohl(ucode->code_length) * 2" multiplication can have an integer overflow.
Red Hat
kernel: crypto: cavium - prevent integer overflow loading firmware
vendor_redhat·2025-09-15·CVSS 5.5
CVE-2022-50330 [MEDIUM] kernel: crypto: cavium - prevent integer overflow loading firmware
kernel: crypto: cavium - prevent integer overflow loading firmware
In the Linux kernel, the following vulnerability has been resolved:
crypto: cavium - prevent integer overflow loading firmware
The "code_length" value comes from the firmware file. If your firmware
is untrusted realistically there is probably very little you can do to
protect yourself. Still we try to limit the damage as much as possible.
Also Smatch marks any data read from the filesystem as untrusted and
prints warnings if it not capped correctly.
The "ntohl(ucode->code_length) * 2" multiplication can have an
integer overflow.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: ker
Ivanti
Ivanti Security Advisory: CVE-2024-50330
vendor_ivanti·2024-11-12·CVSS 9.8
CVE-2024-50330 [CRITICAL] CWE-89 Ivanti Security Advisory: CVE-2024-50330
Ivanti Security Advisory: CVE-2024-50330
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.
CVE IDs: CVE-2024-50330
CVSS Base Score: 9.8
Severity: CRITICAL
CWEs: CWE-89
Debian
CVE-2022-50330: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: cav...
vendor_debian·2022·CVSS 5.5
CVE-2022-50330 [MEDIUM] CVE-2022-50330: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: cav...
In the Linux kernel, the following vulnerability has been resolved: crypto: cavium - prevent integer overflow loading firmware The "code_length" value comes from the firmware file. If your firmware is untrusted realistically there is probably very little you can do to protect yourself. Still we try to limit the damage as much as possible. Also Smatch marks any data read from the filesystem as untrusted and prints warnings if it not capped correctly. The "ntohl(ucode->code_length) * 2" multiplication can have an integer overflow.
Scope: local
bookworm: resolved (fixed in 6.0.3-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved (fixed in 6.0.3-1)
sid: resolved (fixed in 6.0.3-1)
trixie: resolved (fixed in 6.0.3-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/172c8a24fc8312cf6b88d3c88469653fdcb1c127https://git.kernel.org/stable/c/2526d6bf27d15054bb0778b2f7bc6625fd934905https://git.kernel.org/stable/c/371fa5129af53a79f6dddc90fe5bb0825cbe72a4https://git.kernel.org/stable/c/3a720eb89026c5241b8c4abb33370dc6fb565eeehttps://git.kernel.org/stable/c/584561e94260268abe1c83e00d9c205565cb7bc5https://git.kernel.org/stable/c/90e483e7f20c32287d2a9da967e122938f52737ahttps://git.kernel.org/stable/c/c4d4c2afd08dfb3cd1c880d1811ede2568e81a6dhttps://git.kernel.org/stable/c/e29fd7a6852376d2cfb95ad5d6d3eeff93f815e9
2025-09-15
Published