CVE-2022-50494
published 2025-10-04CVE-2022-50494: In the Linux kernel, the following vulnerability has been resolved: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash When…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash
When CPU 0 is offline and intel_powerclamp is used to inject
idle, it generates kernel BUG:
BUG: using smp_processor_id() in preemptible [00000000] code: bash/15687
caller is debug_smp_processor_id+0x17/0x20
CPU: 4 PID: 15687 Comm: bash Not tainted 5.19.0-rc7+ #57
Call Trace:
dump_stack_lvl+0x49/0x63
dump_stack+0x10/0x16
check_preemption_disabled+0xdd/0xe0
debug_smp_processor_id+0x17/0x20
powerclamp_set_cur_state+0x7f/0xf9 [intel_powerclamp]
...
...
Here CPU 0 is the control CPU by default and changed to the current CPU,
if CPU 0 offlined. This check has to be performed under cpus_read_lock(),
hence the above warning.
Use get_cpu() instead of smp_processor_id() to avoid this BUG.
[ rjw: Subject edits ]
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.3-1 (bookworm) | linux 6.0.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 3e799e815097febbcb81b472285be824f5d089f9 | 3e799e815097febbcb81b472285be824f5d089f9 |
| linux | linux | >= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 0f91f66c568b316b19cb042cf50584467b3bdff4 | 0f91f66c568b316b19cb042cf50584467b3bdff4 |
| linux | linux | >= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 6904727db0eb62fb0c2dce1cf331c341d97ee4b7 | 6904727db0eb62fb0c2dce1cf331c341d97ee4b7 |
| linux | linux | >= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 5a646c38f648185ee2c62f2a19da3c6f04e27612 | 5a646c38f648185ee2c62f2a19da3c6f04e27612 |
| linux | linux | >= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 513943bf879d45005213e6f5cfb7d9e9943f589f | 513943bf879d45005213e6f5cfb7d9e9943f589f |
| linux | linux | >= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 5614908434451aafbf9b24cb5247cf1d21269f76 | 5614908434451aafbf9b24cb5247cf1d21269f76 |
| linux | linux | >= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 6e2a347b304224b2aeb1c0ea000d1cf8a02cc592 | 6e2a347b304224b2aeb1c0ea000d1cf8a02cc592 |
| linux | linux | >= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 418fae0700e85a498062424f8656435c32cdb200 | 418fae0700e85a498062424f8656435c32cdb200 |
| linux | linux | >= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 68b99e94a4a2db6ba9b31fe0485e057b9354a640 | 68b99e94a4a2db6ba9b31fe0485e057b9354a640 |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 3.9 < 4.9.331 | 4.9.331 |
| linux | linux_kernel | >= 4.10 < 4.14.296 | 4.14.296 |
| linux | linux_kernel | >= 4.15 < 4.19.262 | 4.19.262 |
| linux | linux_kernel | >= 4.20 < 5.4.220 | 5.4.220 |
| linux | linux_kernel | >= 5.11 < 5.15.75 | 5.15.75 |
| linux | linux_kernel | >= 5.16 < 5.19.17 | 5.19.17 |
| linux | linux_kernel | >= 5.5 < 5.10.150 | 5.10.150 |
| linux | linux_kernel | >= 6.0 < 6.0.3 | 6.0.3 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-256h-gf49-r65r: In the Linux kernel, the following vulnerability has been resolved:
thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid c
ghsa_unreviewed·2025-10-04
CVE-2022-50494 [MEDIUM] GHSA-256h-gf49-r65r: In the Linux kernel, the following vulnerability has been resolved:
thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid c
In the Linux kernel, the following vulnerability has been resolved:
thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash
When CPU 0 is offline and intel_powerclamp is used to inject
idle, it generates kernel BUG:
BUG: using smp_processor_id() in preemptible [00000000] code: bash/15687
caller is debug_smp_processor_id+0x17/0x20
CPU: 4 PID: 15687 Comm: bash Not tainted 5.19.0-rc7+ #57
Call Trace:
dump_stack_lvl+0x49/0x63
dump_stack+0x10/0x16
check_preemption_disabled+0xdd/0xe0
debug_smp_processor_id+0x17/0x20
powerclamp_set_cur_state+0x7f/0xf9 [intel_powerclamp]
...
...
Here CPU 0 is the control CPU by default and changed to the current CPU,
if CPU 0 offlined. This check has to be performed under cpus_read_lock(),
hence the above warning.
Use get_cpu()
OSV
CVE-2022-50494: In the Linux kernel, the following vulnerability has been resolved: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid cr
osv·2025-10-04·CVSS 5.5
CVE-2022-50494 [MEDIUM] CVE-2022-50494: In the Linux kernel, the following vulnerability has been resolved: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid cr
In the Linux kernel, the following vulnerability has been resolved: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash When CPU 0 is offline and intel_powerclamp is used to inject idle, it generates kernel BUG: BUG: using smp_processor_id() in preemptible [00000000] code: bash/15687 caller is debug_smp_processor_id+0x17/0x20 CPU: 4 PID: 15687 Comm: bash Not tainted 5.19.0-rc7+ #57 Call Trace: dump_stack_lvl+0x49/0x63 dump_stack+0x10/0x16 check_preemption_disabled+0xdd/0xe0 debug_smp_processor_id+0x17/0x20 powerclamp_set_cur_state+0x7f/0xf9 [intel_powerclamp] ... ... Here CPU 0 is the control CPU by default and changed to the current CPU, if CPU 0 offlined. This check has to be performed under cpus_read_lock(), hence the above warning. Use get_cpu() instea
Red Hat
kernel: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash
vendor_redhat·2025-10-04·CVSS 5.5
CVE-2022-50494 [MEDIUM] kernel: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash
kernel: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash
In the Linux kernel, the following vulnerability has been resolved:
thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash
When CPU 0 is offline and intel_powerclamp is used to inject
idle, it generates kernel BUG:
BUG: using smp_processor_id() in preemptible [00000000] code: bash/15687
caller is debug_smp_processor_id+0x17/0x20
CPU: 4 PID: 15687 Comm: bash Not tainted 5.19.0-rc7+ #57
Call Trace:
dump_stack_lvl+0x49/0x63
dump_stack+0x10/0x16
check_preemption_disabled+0xdd/0xe0
debug_smp_processor_id+0x17/0x20
powerclamp_set_cur_state+0x7f/0xf9 [intel_powerclamp]
...
...
Here CPU 0 is the control CPU by default and changed to the current CPU,
if CPU 0 offlined. This
Debian
CVE-2022-50494: linux - In the Linux kernel, the following vulnerability has been resolved: thermal: in...
vendor_debian·2022·CVSS 5.5
CVE-2022-50494 [MEDIUM] CVE-2022-50494: linux - In the Linux kernel, the following vulnerability has been resolved: thermal: in...
In the Linux kernel, the following vulnerability has been resolved: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash When CPU 0 is offline and intel_powerclamp is used to inject idle, it generates kernel BUG: BUG: using smp_processor_id() in preemptible [00000000] code: bash/15687 caller is debug_smp_processor_id+0x17/0x20 CPU: 4 PID: 15687 Comm: bash Not tainted 5.19.0-rc7+ #57 Call Trace: dump_stack_lvl+0x49/0x63 dump_stack+0x10/0x16 check_preemption_disabled+0xdd/0xe0 debug_smp_processor_id+0x17/0x20 powerclamp_set_cur_state+0x7f/0xf9 [intel_powerclamp] ... ... Here CPU 0 is the control CPU by default and changed to the current CPU, if CPU 0 offlined. This check has to be performed under cpus_read_lock(), hence the above warning. Use get_cpu() instea
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/0f91f66c568b316b19cb042cf50584467b3bdff4https://git.kernel.org/stable/c/3e799e815097febbcb81b472285be824f5d089f9https://git.kernel.org/stable/c/418fae0700e85a498062424f8656435c32cdb200https://git.kernel.org/stable/c/513943bf879d45005213e6f5cfb7d9e9943f589fhttps://git.kernel.org/stable/c/5614908434451aafbf9b24cb5247cf1d21269f76https://git.kernel.org/stable/c/5a646c38f648185ee2c62f2a19da3c6f04e27612https://git.kernel.org/stable/c/68b99e94a4a2db6ba9b31fe0485e057b9354a640https://git.kernel.org/stable/c/6904727db0eb62fb0c2dce1cf331c341d97ee4b7https://git.kernel.org/stable/c/6e2a347b304224b2aeb1c0ea000d1cf8a02cc592
2025-10-04
Published