CVE-2022-50580Integer Overflow or Wraparound in Linux

Severity
5.5MEDIUM
No vector
EPSS
0.0%
top 91.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22

Description

In the Linux kernel, the following vulnerability has been resolved: blk-throttle: prevent overflow while calculating wait time There is a problem found by code review in tg_with_in_bps_limit() that 'bps_limit * jiffy_elapsed_rnd' might overflow. Fix the problem by calling mul_u64_u64_div_u64() instead.

Affected Packages4 packages

Linuxlinux/linux_kernel2.6.375.10.150+3
Debianlinux/linux_kernel< 5.10.158-1+3
CVEListV5linux/linuxe43473b7f223ec866f7db273697e76c337c390f919c010ae44f0ce52b5436080492a61a092ee0cf4+5
debiandebian/linux< linux 6.0.3-1 (bookworm)

🔴Vulnerability Details

3
OSV
CVE-2022-50580: In the Linux kernel, the following vulnerability has been resolved: blk-throttle: prevent overflow while calculating wait time There is a problem foun2025-10-22
GHSA
GHSA-99r7-2gxr-89fw: In the Linux kernel, the following vulnerability has been resolved: blk-throttle: prevent overflow while calculating wait time There is a problem fo2025-10-22
OSV
blk-throttle: prevent overflow while calculating wait time2025-10-22

📋Vendor Advisories

2
Red Hat
kernel: blk-throttle: prevent overflow while calculating wait time2025-10-22
Debian
CVE-2022-50580: linux - In the Linux kernel, the following vulnerability has been resolved: blk-throttl...2022