PT-2025-25890 · Linux+4 · Linux Kernel+4

Published

2022-08-23

·

Updated

2025-07-28

·

CVE-2022-49964

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.19.0-10393-g7c2a8d3ac4c0
Description The issue arises from the incorrect assignment of a signed error value to an unsigned variable fw level in the Linux kernel's cacheinfo module for arm64 architecture. This occurs because the function acpi find last cache level() returns a signed value, which can be negative if no PPTT table is found, but this value is then assigned to the unsigned fw level. As a result, the number of cache leaves is calculated incorrectly, leading to a huge value that causes a warning from alloc pages due to an order greater than MAX ORDER. This warning is triggered during the execution of alloc pages+0x74/0x314 and is related to memory allocation.
Recommendations To resolve this issue, update the Linux kernel to a version where the fw level is changed to a signed integer, allowing for the correct handling of error values returned by acpi find last cache level(). Specifically, apply the fix introduced in commit 0c80f9e165f8 to ensure that errors are properly returned from init cache level() and that the fw level variable is signed to accommodate potential negative error values.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02347
CESA-2023_2951
CVE-2022-49964
OESA-2025-1820
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse