Home

Description

In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource() As 'kdata.num' is user-controlled data, if user tries to allocate memory larger than(>=) MAX_ORDER, then kcalloc() will fail, it creates a stack trace and messes up dmesg with a warning. Call trace: -> privcmd_ioctl --> privcmd_ioctl_mmap_resource Add __GFP_NOWARN in order to avoid too large allocation warning. This is detected by static analysis using smatch.

PUBLISHED Reserved 2025-10-22 | Published 2025-10-22 | Updated 2025-10-22 | Assigner Linux

Product status

Default status
unaffected

3ad0876554cafa368f574d4d408468510543e9ff (git) before 5d68ae32d132ea2af73bc223fd64c46f85302a8b
affected

3ad0876554cafa368f574d4d408468510543e9ff (git) before 4f983ee5e5de924d93a7bbb4e6f68f38c6256cd5
affected

3ad0876554cafa368f574d4d408468510543e9ff (git) before 46026bb057c35f5bb111bf95e00cd8366d2e34d4
affected

3ad0876554cafa368f574d4d408468510543e9ff (git) before 0bf874183b32eae2cc20e3c5be38ec3d33e7e564
affected

3ad0876554cafa368f574d4d408468510543e9ff (git) before e0c5f1058ed96f2b7487560c4c4cbd768d13d065
affected

3ad0876554cafa368f574d4d408468510543e9ff (git) before 4da411086f5ab32f811a89ef804980ec106ebb65
affected

3ad0876554cafa368f574d4d408468510543e9ff (git) before 8b997b2bb2c53b76a6db6c195930e9ab8e4b0c79
affected

Default status
affected

4.18
affected

Any version before 4.18
unaffected

4.19.270 (semver)
unaffected

5.4.229 (semver)
unaffected

5.10.163 (semver)
unaffected

5.15.86 (semver)
unaffected

6.0.16 (semver)
unaffected

6.1.2 (semver)
unaffected

6.2 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/5d68ae32d132ea2af73bc223fd64c46f85302a8b

git.kernel.org/...c/4f983ee5e5de924d93a7bbb4e6f68f38c6256cd5

git.kernel.org/...c/46026bb057c35f5bb111bf95e00cd8366d2e34d4

git.kernel.org/...c/0bf874183b32eae2cc20e3c5be38ec3d33e7e564

git.kernel.org/...c/e0c5f1058ed96f2b7487560c4c4cbd768d13d065

git.kernel.org/...c/4da411086f5ab32f811a89ef804980ec106ebb65

git.kernel.org/...c/8b997b2bb2c53b76a6db6c195930e9ab8e4b0c79

cve.org (CVE-2022-50575)

nvd.nist.gov (CVE-2022-50575)

Download JSON