cbcvebase.
CVE-2022-50494
published 2025-10-04

CVE-2022-50494: In the Linux kernel, the following vulnerability has been resolved: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash When…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.7th percentile
In the Linux kernel, the following vulnerability has been resolved: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash When CPU 0 is offline and intel_powerclamp is used to inject idle, it generates kernel BUG: BUG: using smp_processor_id() in preemptible [00000000] code: bash/15687 caller is debug_smp_processor_id+0x17/0x20 CPU: 4 PID: 15687 Comm: bash Not tainted 5.19.0-rc7+ #57 Call Trace: dump_stack_lvl+0x49/0x63 dump_stack+0x10/0x16 check_preemption_disabled+0xdd/0xe0 debug_smp_processor_id+0x17/0x20 powerclamp_set_cur_state+0x7f/0xf9 [intel_powerclamp] ... ... Here CPU 0 is the control CPU by default and changed to the current CPU, if CPU 0 offlined. This check has to be performed under cpus_read_lock(), hence the above warning. Use get_cpu() instead of smp_processor_id() to avoid this BUG. [ rjw: Subject edits ]

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux>= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 3e799e815097febbcb81b472285be824f5d089f93e799e815097febbcb81b472285be824f5d089f9
linuxlinux>= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 0f91f66c568b316b19cb042cf50584467b3bdff40f91f66c568b316b19cb042cf50584467b3bdff4
linuxlinux>= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 6904727db0eb62fb0c2dce1cf331c341d97ee4b76904727db0eb62fb0c2dce1cf331c341d97ee4b7
linuxlinux>= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 5a646c38f648185ee2c62f2a19da3c6f04e276125a646c38f648185ee2c62f2a19da3c6f04e27612
linuxlinux>= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 513943bf879d45005213e6f5cfb7d9e9943f589f513943bf879d45005213e6f5cfb7d9e9943f589f
linuxlinux>= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 5614908434451aafbf9b24cb5247cf1d21269f765614908434451aafbf9b24cb5247cf1d21269f76
linuxlinux>= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 6e2a347b304224b2aeb1c0ea000d1cf8a02cc5926e2a347b304224b2aeb1c0ea000d1cf8a02cc592
linuxlinux>= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 418fae0700e85a498062424f8656435c32cdb200418fae0700e85a498062424f8656435c32cdb200
linuxlinux>= d6d71ee4a14ae602db343ec48c491851d7ec5267 < 68b99e94a4a2db6ba9b31fe0485e057b9354a64068b99e94a4a2db6ba9b31fe0485e057b9354a640
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 3.9 < 4.9.3314.9.331
linuxlinux_kernel>= 4.10 < 4.14.2964.14.296
linuxlinux_kernel>= 4.15 < 4.19.2624.19.262
linuxlinux_kernel>= 4.20 < 5.4.2205.4.220
linuxlinux_kernel>= 5.11 < 5.15.755.15.75
linuxlinux_kernel>= 5.16 < 5.19.175.19.17
linuxlinux_kernel>= 5.5 < 5.10.1505.10.150
linuxlinux_kernel>= 6.0 < 6.0.36.0.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.