CVE-2022-50167

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
18/06/2025
Last modified:
17/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> bpf: fix potential 32-bit overflow when accessing ARRAY map element<br /> <br /> If BPF array map is bigger than 4GB, element pointer calculation can<br /> overflow because both index and elem_size are u32. Fix this everywhere<br /> by forcing 64-bit multiplication. Extract this formula into separate<br /> small helper and use it consistently in various places.<br /> <br /> Speculative-preventing formula utilizing index_mask trick is left as is,<br /> but explicit u64 casts are added in both places.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.3 (including) 5.18.18 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.19 (including) 5.19.2 (excluding)