cbcvebase.
CVE-2022-50366
published 2025-09-17

CVE-2022-50366: In the Linux kernel, the following vulnerability has been resolved: powercap: intel_rapl: fix UBSAN shift-out-of-bounds issue When value < time_unit, the…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.20%
10.1th percentile
In the Linux kernel, the following vulnerability has been resolved: powercap: intel_rapl: fix UBSAN shift-out-of-bounds issue When value < time_unit, the parameter of ilog2() will be zero and the return value is -1. u64(-1) is too large for shift exponent and then will trigger shift-out-of-bounds: shift exponent 18446744073709551615 is too large for 32-bit type 'int' Call Trace: rapl_compute_time_window_core rapl_write_data_raw set_time_window store_constraint_time_window_us

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux>= 2d281d8196e38dd3a4ee9af26621ddde8329f269 < 42f79dbb9514f726ff21df25f09cb0693b0b244542f79dbb9514f726ff21df25f09cb0693b0b2445
linuxlinux>= 2d281d8196e38dd3a4ee9af26621ddde8329f269 < 3eb0ba70376f6ee40fa843fc9cee49269370b0b33eb0ba70376f6ee40fa843fc9cee49269370b0b3
linuxlinux>= 2d281d8196e38dd3a4ee9af26621ddde8329f269 < 4ebba43384722adbd325baec3a12c572d94488eb4ebba43384722adbd325baec3a12c572d94488eb
linuxlinux>= 2d281d8196e38dd3a4ee9af26621ddde8329f269 < 49a6ffdaed60f0eb52c198fafebc05994e16e30549a6ffdaed60f0eb52c198fafebc05994e16e305
linuxlinux>= 2d281d8196e38dd3a4ee9af26621ddde8329f269 < 708b9abe1b4a2f050a483db4b7edfc446b13df1f708b9abe1b4a2f050a483db4b7edfc446b13df1f
linuxlinux>= 2d281d8196e38dd3a4ee9af26621ddde8329f269 < 139bbbd01114433b80fe59f5e1330615aadf9752139bbbd01114433b80fe59f5e1330615aadf9752
linuxlinux>= 2d281d8196e38dd3a4ee9af26621ddde8329f269 < 6216b685b8f48ab7b721a6fd5acbf526b41c13e86216b685b8f48ab7b721a6fd5acbf526b41c13e8
linuxlinux>= 2d281d8196e38dd3a4ee9af26621ddde8329f269 < 1d94af37565e4d3c26b0d63428e093a37d5b4c321d94af37565e4d3c26b0d63428e093a37d5b4c32
linuxlinux>= 2d281d8196e38dd3a4ee9af26621ddde8329f269 < 2d93540014387d1c73b9ccc4d7895320df66d01b2d93540014387d1c73b9ccc4d7895320df66d01b
linuxlinux_kernel< 4.9.3314.9.331
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 4.10 < 4.14.2964.14.296
linuxlinux_kernel>= 4.15 < 4.19.2624.19.262
linuxlinux_kernel>= 4.20 < 5.4.2205.4.220
linuxlinux_kernel>= 5.11 < 5.15.755.15.75
linuxlinux_kernel>= 5.16 < 5.19.175.19.17
linuxlinux_kernel>= 5.5 < 5.10.1505.10.150
linuxlinux_kernel>= 6.0 < 6.0.36.0.3

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.