PT-2025-26019 · Linux+4 · Linux Kernel+4

Published

2022-07-12

·

Updated

2025-07-28

·

CVE-2022-50093

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.19.0-rc3-00004-g0e862838f290
Description A vulnerability in the Linux kernel has been resolved, which could lead to invalid memory access via node online(NUMA NO NODE). The issue occurs when pxm to node() returns %NUMA NO NODE (-1), a valid 'magic' number for a NUMA node but not a valid bit number for use in bitops. This can cause an insane array index when calculating the bit position in memory. The vulnerability is related to the dmar parse one rhsa function in drivers/iommu/intel/dmar.c.
Recommendations For Linux kernel versions prior to 5.19.0-rc3-00004-g0e862838f290, consider updating to a newer version that includes the fix for this issue. As a temporary workaround, consider adding an explicit check for the node being not %NUMA NO NODE before calling test bit(). Restrict access to the dmar parse one rhsa function in drivers/iommu/intel/dmar.c to minimize the risk of exploitation. Avoid using the node online function with unvalidated input until the issue is resolved.

Exploit

Fix

Out of bounds Read

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02806
CESA-2023_2951
CVE-2022-50093
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
SUSE-SU-2025:02264-1
SUSE-SU-2025:02308-1
SUSE-SU-2025:02320-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02334-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02308-1
SUSE-SU-2025_02334-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse