cbcvebase.
CVE-2022-50849
published 2025-12-30

CVE-2022-50849: In the Linux kernel, the following vulnerability has been resolved: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP An oops can be induced by running…

PriorityP423medium5.9
EPSS
0.20%
10.4th percentile
In the Linux kernel, the following vulnerability has been resolved: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP An oops can be induced by running 'cat /proc/kcore > /dev/null' on devices using pstore with the ram backend because kmap_atomic() assumes lowmem pages are accessible with __va(). Unable to handle kernel paging request at virtual address ffffff807ff2b000 Mem abort info: ESR = 0x96000006 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x06: level 2 translation fault Data abort info: ISV = 0, ISS = 0x00000006 CM = 0, WnR = 0 swapper pgtable: 4k pages, 39-bit VAs, pgdp=0000000081d87000 [ffffff807ff2b000] pgd=180000017fe18003, p4d=180000017fe18003, pud=180000017fe18003, pmd=0000000000000000 Internal error: Oops: 96000006 [#1] PREEMPT SMP Modules linked in: dm_integrity CPU: 7 PID: 21179 Comm: perf Not tainted 5.15.67-10882-ge4eb2eb988cd #1 baa443fb8e8477896a370b31a821eb2009f9bfba Hardware name: Google Lazor (rev3 - 8) (DT) pstate: a0400009 (NzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : __memcpy+0x110/0x260 lr : vread+0x194/0x294 sp : ffffffc013ee39d0 x29: ffffffc013ee39f0 x28: 0000000000001000 x27: ffffff807ff2b000 x26: 0000000000001000 x25: ffffffc0085a2000 x24: ffffff802d4b3000 x23: ffffff80f8a60000 x22: ffffff802d4b3000 x21: ffffffc0085a2000 x20: ffffff8080b7bc68 x19: 0000000000001000 x18: 0000000000000000 x17: 0000000000000000 x16: 0000000000000000 x15: ffffffd3073f2e60 x14: ffffffffad588000 x13: 0000000000000000 x12: 0000000000000001 x11: 00000000000001a2 x10: 00680000fff2bf0b x9 : 03fffffff807ff2b x8 : 0000000000000001 x7 : 0000000000000000 x6 : 0000000000000000 x5 : ffffff802d4b4000 x4 : ffffff807ff2c000 x3 : ffffffc013ee3a78 x2 : 0000000000001000 x1 : ffffff807ff2b000 x0 : ffffff802d4b3000 Call trace: __memcpy+0x110/0x260 read_kcore+0x584/0x778 proc_reg_read+0xb4/0xe4 During early boot, memblock reserves the pages for the ramoops reserved memory node in DT that would otherwise be part of the direct

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 404a6043385de17273624b076599669db5ad891f < 1579bed1613802a323a1e14567faa95c149e105e1579bed1613802a323a1e14567faa95c149e105e
linuxlinux>= 404a6043385de17273624b076599669db5ad891f < fdebcc33b663d2e8da937653ddfbfc1315047eaafdebcc33b663d2e8da937653ddfbfc1315047eaa
linuxlinux>= 404a6043385de17273624b076599669db5ad891f < 6d9460214e363e1f3d0756ee5d947e76e3e6f86c6d9460214e363e1f3d0756ee5d947e76e3e6f86c
linuxlinux>= 404a6043385de17273624b076599669db5ad891f < 4d3126f242a0090342ffe925c35fb4f4252b75624d3126f242a0090342ffe925c35fb4f4252b7562
linuxlinux>= 404a6043385de17273624b076599669db5ad891f < 295f59cd2cdeed841850d02dddde3a122cbf6fc6295f59cd2cdeed841850d02dddde3a122cbf6fc6
linuxlinux>= 404a6043385de17273624b076599669db5ad891f < ebc73c4f266281e2cad1a372ecd81572d95375b6ebc73c4f266281e2cad1a372ecd81572d95375b6
linuxlinux>= 404a6043385de17273624b076599669db5ad891f < 69dbff7d2681c55a4d979fd9b75576303e69979f69dbff7d2681c55a4d979fd9b75576303e69979f
linuxlinux>= 404a6043385de17273624b076599669db5ad891f < 2f82381d0681b10f9ddd27be98c27363b5a3cd1c2f82381d0681b10f9ddd27be98c27363b5a3cd1c
linuxlinux>= 404a6043385de17273624b076599669db5ad891f < e6b842741b4f39007215fd7e545cb55aa3d358a2e6b842741b4f39007215fd7e545cb55aa3d358a2
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 3.4.0 < 4.9.3374.9.337
linuxlinux_kernel>= 4.10.0 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15.0 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11.0 < 5.15.865.15.86
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 5.5.0 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.