CVE-2022-50494 Details
Description
In the Linux kernel, the following vulnerability has been resolved: thermal: intel_powerclamp: Use get_cpu() instead of smp_processor_id() to avoid crash When CPU 0 is offline and intel_powerclamp is used to inject idle, it generates kernel BUG: BUG: using smp_processor_id() in preemptible [00000000] code: bash/15687 caller is debug_smp_processor_id+0x17/0x20 CPU: 4 PID: 15687 Comm: bash Not tainted 5.19.0-rc7+ #57 Call Trace: <TASK> dump_stack_lvl+0x49/0x63 dump_stack+0x10/0x16 check_preemption_disabled+0xdd/0xe0 debug_smp_processor_id+0x17/0x20 powerclamp_set_cur_state+0x7f/0xf9 [intel_powerclamp] ... ... Here CPU 0 is the control CPU by default and changed to the current CPU, if CPU 0 offlined. This check has to be performed under cpus_read_lock(), hence the above warning. Use get_cpu() instead of smp_processor_id() to avoid this BUG. [ rjw: Subject edits ]
A vulnerability in the Linux kernel's intel_powerclamp thermal driver can lead to a system crash. This issue occurs when CPU 0 is offline and the driver is used to inject idle time, causing a kernel bug. The problem arises from using 'smp_processor_id()' in preemptible code, which can generate a kernel panic. The vulnerability affects several versions of the Linux kernel, including 5.19.0-rc7+.
The vulnerability has been addressed by modifying the intel_powerclamp driver to use 'get_cpu()' instead of 'smp_processor_id()'. Users should update to the latest version of the Linux kernel where this fix has been applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0f91f66c568b316b19cb042cf50584467b3bdff4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/3e799e815097febbcb81b472285be824f5d089f9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/418fae0700e85a498062424f8656435c32cdb200 | kernel.org | Patch |
| https://git.kernel.org/stable/c/513943bf879d45005213e6f5cfb7d9e9943f589f | kernel.org | Patch |
| https://git.kernel.org/stable/c/5614908434451aafbf9b24cb5247cf1d21269f76 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5a646c38f648185ee2c62f2a19da3c6f04e27612 | kernel.org | Patch |
| https://git.kernel.org/stable/c/68b99e94a4a2db6ba9b31fe0485e057b9354a640 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6904727db0eb62fb0c2dce1cf331c341d97ee4b7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6e2a347b304224b2aeb1c0ea000d1cf8a02cc592 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.9, < 4.9.331 >= 4.10, < 4.14.296 >= 4.15, < 4.19.262 >= 4.20, < 5.4.220 >= 5.5, < 5.10.150 >= 5.11, < 5.15.75 >= 5.16, < 5.19.17 >= 6.0, < 6.0.3 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jan 23, 2026 | Initial Analysis | [email protected] |
| Oct 4, 2025 | New CVE Received | kernel.org |