CVE-2022-50849
published 2025-12-30CVE-2022-50849: In the Linux kernel, the following vulnerability has been resolved: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP An oops can be induced by running…
PriorityP423medium5.9
EPSS
0.20%
10.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
An oops can be induced by running 'cat /proc/kcore > /dev/null' on
devices using pstore with the ram backend because kmap_atomic() assumes
lowmem pages are accessible with __va().
Unable to handle kernel paging request at virtual address ffffff807ff2b000
Mem abort info:
ESR = 0x96000006
EC = 0x25: DABT (current EL), IL = 32 bits
SET = 0, FnV = 0
EA = 0, S1PTW = 0
FSC = 0x06: level 2 translation fault
Data abort info:
ISV = 0, ISS = 0x00000006
CM = 0, WnR = 0
swapper pgtable: 4k pages, 39-bit VAs, pgdp=0000000081d87000
[ffffff807ff2b000] pgd=180000017fe18003, p4d=180000017fe18003, pud=180000017fe18003, pmd=0000000000000000
Internal error: Oops: 96000006 [#1] PREEMPT SMP
Modules linked in: dm_integrity
CPU: 7 PID: 21179 Comm: perf Not tainted 5.15.67-10882-ge4eb2eb988cd #1 baa443fb8e8477896a370b31a821eb2009f9bfba
Hardware name: Google Lazor (rev3 - 8) (DT)
pstate: a0400009 (NzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : __memcpy+0x110/0x260
lr : vread+0x194/0x294
sp : ffffffc013ee39d0
x29: ffffffc013ee39f0 x28: 0000000000001000 x27: ffffff807ff2b000
x26: 0000000000001000 x25: ffffffc0085a2000 x24: ffffff802d4b3000
x23: ffffff80f8a60000 x22: ffffff802d4b3000 x21: ffffffc0085a2000
x20: ffffff8080b7bc68 x19: 0000000000001000 x18: 0000000000000000
x17: 0000000000000000 x16: 0000000000000000 x15: ffffffd3073f2e60
x14: ffffffffad588000 x13: 0000000000000000 x12: 0000000000000001
x11: 00000000000001a2 x10: 00680000fff2bf0b x9 : 03fffffff807ff2b
x8 : 0000000000000001 x7 : 0000000000000000 x6 : 0000000000000000
x5 : ffffff802d4b4000 x4 : ffffff807ff2c000 x3 : ffffffc013ee3a78
x2 : 0000000000001000 x1 : ffffff807ff2b000 x0 : ffffff802d4b3000
Call trace:
__memcpy+0x110/0x260
read_kcore+0x584/0x778
proc_reg_read+0xb4/0xe4
During early boot, memblock reserves the pages for the ramoops reserved
memory node in DT that would otherwise be part of the direct
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 404a6043385de17273624b076599669db5ad891f < 1579bed1613802a323a1e14567faa95c149e105e | 1579bed1613802a323a1e14567faa95c149e105e |
| linux | linux | >= 404a6043385de17273624b076599669db5ad891f < fdebcc33b663d2e8da937653ddfbfc1315047eaa | fdebcc33b663d2e8da937653ddfbfc1315047eaa |
| linux | linux | >= 404a6043385de17273624b076599669db5ad891f < 6d9460214e363e1f3d0756ee5d947e76e3e6f86c | 6d9460214e363e1f3d0756ee5d947e76e3e6f86c |
| linux | linux | >= 404a6043385de17273624b076599669db5ad891f < 4d3126f242a0090342ffe925c35fb4f4252b7562 | 4d3126f242a0090342ffe925c35fb4f4252b7562 |
| linux | linux | >= 404a6043385de17273624b076599669db5ad891f < 295f59cd2cdeed841850d02dddde3a122cbf6fc6 | 295f59cd2cdeed841850d02dddde3a122cbf6fc6 |
| linux | linux | >= 404a6043385de17273624b076599669db5ad891f < ebc73c4f266281e2cad1a372ecd81572d95375b6 | ebc73c4f266281e2cad1a372ecd81572d95375b6 |
| linux | linux | >= 404a6043385de17273624b076599669db5ad891f < 69dbff7d2681c55a4d979fd9b75576303e69979f | 69dbff7d2681c55a4d979fd9b75576303e69979f |
| linux | linux | >= 404a6043385de17273624b076599669db5ad891f < 2f82381d0681b10f9ddd27be98c27363b5a3cd1c | 2f82381d0681b10f9ddd27be98c27363b5a3cd1c |
| linux | linux | >= 404a6043385de17273624b076599669db5ad891f < e6b842741b4f39007215fd7e545cb55aa3d358a2 | e6b842741b4f39007215fd7e545cb55aa3d358a2 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 3.4.0 < 4.9.337 | 4.9.337 |
| linux | linux_kernel | >= 4.10.0 < 4.14.303 | 4.14.303 |
| linux | linux_kernel | >= 4.15.0 < 4.19.270 | 4.19.270 |
| linux | linux_kernel | >= 4.20.0 < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 5.11.0 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 5.16.0 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 5.5.0 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 6.1.0 < 6.1.2 | 6.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
vendor_redhat·2025-12-30·CVSS 5.9
CVE-2022-50849 [MEDIUM] CWE-119 kernel: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
kernel: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
In the Linux kernel, the following vulnerability has been resolved:
pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
An oops can be induced by running 'cat /proc/kcore > /dev/null' on
devices using pstore with the ram backend because kmap_atomic() assumes
lowmem pages are accessible with __va().
Unable to handle kernel paging request at virtual address ffffff807ff2b000
Mem abort info:
ESR = 0x96000006
EC = 0x25: DABT (current EL), IL = 32 bits
SET = 0, FnV = 0
EA = 0, S1PTW = 0
FSC = 0x06: level 2 translation fault
Data abort info:
ISV = 0, ISS = 0x00000006
CM = 0, WnR = 0
swapper pgtable: 4k pages, 39-bit VAs, pgdp=0000000081d87000
[ffffff807ff2b000] pgd=180000017fe18003, p4d=180000017fe18003, pud=180000017fe18003, pmd=00
Debian
CVE-2022-50849: linux - In the Linux kernel, the following vulnerability has been resolved: pstore: Avo...
vendor_debian·2022
CVE-2022-50849 CVE-2022-50849: linux - In the Linux kernel, the following vulnerability has been resolved: pstore: Avo...
In the Linux kernel, the following vulnerability has been resolved: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP An oops can be induced by running 'cat /proc/kcore > /dev/null' on devices using pstore with the ram backend because kmap_atomic() assumes lowmem pages are accessible with __va(). Unable to handle kernel paging request at virtual address ffffff807ff2b000 Mem abort info: ESR = 0x96000006 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x06: level 2 translation fault Data abort info: ISV = 0, ISS = 0x00000006 CM = 0, WnR = 0 swapper pgtable: 4k pages, 39-bit VAs, pgdp=0000000081d87000 [ffffff807ff2b000] pgd=180000017fe18003, p4d=180000017fe18003, pud=180000017fe18003, pmd=0000000000000000 Internal error: Oops: 96000006 [#1] PREEMPT SMP
VulDB
Linux Kernel up to 6.1.1 vmap state issue (Nessus ID 281535 / WID-SEC-2025-2941)
vuldb·2026-04-26
CVE-2022-50849 [CRITICAL] Linux Kernel up to 6.1.1 vmap state issue (Nessus ID 281535 / WID-SEC-2025-2941)
A vulnerability identified as critical has been detected in Linux Kernel up to 6.1.1. This impacts the function vmap. This manipulation causes state issue.
The identification of this vulnerability is CVE-2022-50849. The attack needs to be done within the local network. There is no exploit available.
You should upgrade the affected component.
OSV
CVE-2022-50849: In the Linux kernel, the following vulnerability has been resolved: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP An oops can be induced by ru
osv·2025-12-30
CVE-2022-50849 CVE-2022-50849: In the Linux kernel, the following vulnerability has been resolved: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP An oops can be induced by ru
In the Linux kernel, the following vulnerability has been resolved: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP An oops can be induced by running 'cat /proc/kcore > /dev/null' on devices using pstore with the ram backend because kmap_atomic() assumes lowmem pages are accessible with __va(). Unable to handle kernel paging request at virtual address ffffff807ff2b000 Mem abort info: ESR = 0x96000006 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x06: level 2 translation fault Data abort info: ISV = 0, ISS = 0x00000006 CM = 0, WnR = 0 swapper pgtable: 4k pages, 39-bit VAs, pgdp=0000000081d87000 [ffffff807ff2b000] pgd=180000017fe18003, p4d=180000017fe18003, pud=180000017fe18003, pmd=0000000000000000 Internal error: Oops: 96000006 [#1] PREEMPT SMP
GHSA
GHSA-pm3x-6f4f-jm2x: In the Linux kernel, the following vulnerability has been resolved:
pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
An oops can be induced by
ghsa_unreviewed·2025-12-30
CVE-2022-50849 GHSA-pm3x-6f4f-jm2x: In the Linux kernel, the following vulnerability has been resolved:
pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
An oops can be induced by
In the Linux kernel, the following vulnerability has been resolved:
pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
An oops can be induced by running 'cat /proc/kcore > /dev/null' on
devices using pstore with the ram backend because kmap_atomic() assumes
lowmem pages are accessible with __va().
Unable to handle kernel paging request at virtual address ffffff807ff2b000
Mem abort info:
ESR = 0x96000006
EC = 0x25: DABT (current EL), IL = 32 bits
SET = 0, FnV = 0
EA = 0, S1PTW = 0
FSC = 0x06: level 2 translation fault
Data abort info:
ISV = 0, ISS = 0x00000006
CM = 0, WnR = 0
swapper pgtable: 4k pages, 39-bit VAs, pgdp=0000000081d87000
[ffffff807ff2b000] pgd=180000017fe18003, p4d=180000017fe18003, pud=180000017fe18003, pmd=0000000000000000
Internal error: Oops: 96000006 [#1] PREEMPT S
OSV
pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
osv·2025-12-30
CVE-2022-50849 pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
In the Linux kernel, the following vulnerability has been resolved:
pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
An oops can be induced by running 'cat /proc/kcore > /dev/null' on
devices using pstore with the ram backend because kmap_atomic() assumes
lowmem pages are accessible with __va().
Unable to handle kernel paging request at virtual address ffffff807ff2b000
Mem abort info:
ESR = 0x96000006
EC = 0x25: DABT (current EL), IL = 32 bits
SET = 0, FnV = 0
EA = 0, S1PTW = 0
FSC = 0x06: level 2 translation fault
Data abort info:
ISV = 0, ISS = 0x00000006
CM = 0, WnR = 0
swapper pgtable: 4k pages, 39-bit VAs, pgdp=0000000081d87000
[ffffff807ff2b000] pgd=180000017fe18003, p4d=180000017fe18003, pud=180000017fe18003, pmd=0000000
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-50849 kernel: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
bugzilla·2025-12-30
CVE-2022-50849 [MEDIUM] CVE-2022-50849 kernel: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
CVE-2022-50849 kernel: pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
In the Linux kernel, the following vulnerability has been resolved:
pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
An oops can be induced by running 'cat /proc/kcore > /dev/null' on
devices using pstore with the ram backend because kmap_atomic() assumes
lowmem pages are accessible with __va().
Unable to handle kernel paging request at virtual address ffffff807ff2b000
Mem abort info:
ESR = 0x96000006
EC = 0x25: DABT (current EL), IL = 32 bits
SET = 0, FnV = 0
EA = 0, S1PTW = 0
FSC = 0x06: level 2 translation fault
Data abort info:
ISV = 0, ISS = 0x00000006
CM = 0, WnR = 0
swapper pgtable: 4k pages, 39-bit VAs, pgdp=0000000081d87000
[ffffff807ff2b000] pgd=180000017fe18003, p4d=180000017fe18003, pud=180000
Wiz
CVE-2022-50849 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50849 CVE-2022-50849 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50849 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
pstore: Avoid kcore oops by vmap()ing with VM_IOREMAP
An oops can be induced by running 'cat /proc/kcore > /dev/null' on
devices using pstore with the ram backend because kmap_atomic() assumes
lowmem pages are accessible with __va().
Unable to handle kernel paging request at virtual address ffffff807ff2b000
Mem abort info:
ESR = 0x96000006
EC = 0x25: DABT (current EL), IL = 32 bits
SET = 0, FnV = 0
EA = 0, S1PTW = 0
FSC = 0x06: level 2 translation fault
Data abort info:
ISV = 0, ISS = 0x00000006
CM = 0, WnR = 0
swapper pgtable: 4k pages, 39-bit VAs, pgdp=0000000081d87000
[ffffff807ff2b000] pgd=180000017fe18003, p4d=180000017fe18003, pud=180000017fe
https://git.kernel.org/stable/c/1579bed1613802a323a1e14567faa95c149e105ehttps://git.kernel.org/stable/c/295f59cd2cdeed841850d02dddde3a122cbf6fc6https://git.kernel.org/stable/c/2f82381d0681b10f9ddd27be98c27363b5a3cd1chttps://git.kernel.org/stable/c/4d3126f242a0090342ffe925c35fb4f4252b7562https://git.kernel.org/stable/c/69dbff7d2681c55a4d979fd9b75576303e69979fhttps://git.kernel.org/stable/c/6d9460214e363e1f3d0756ee5d947e76e3e6f86chttps://git.kernel.org/stable/c/e6b842741b4f39007215fd7e545cb55aa3d358a2https://git.kernel.org/stable/c/ebc73c4f266281e2cad1a372ecd81572d95375b6https://git.kernel.org/stable/c/fdebcc33b663d2e8da937653ddfbfc1315047eaa
2025-12-30
Published