CVE-2022-49748
Linux Kernel vulnerability analysis and mitigation

Overview

In the Linux kernel, a potential integer overflow vulnerability was identified in the perf/x86/amd component, tracked as CVE-2022-49748. The issue involves the left shift of a 32-bit integer constant 1 being evaluated using 32-bit arithmetic before being passed as a 64-bit function argument. When the value of 'i' is 32 or greater, this can lead to an overflow condition (NVD).

Technical details

The vulnerability stems from an arithmetic operation where a 32-bit integer constant 1 is left-shifted and then passed as a 64-bit function argument. The issue occurs specifically in the perf/x86/amd component of the Linux kernel. When the shift amount 'i' is 32 or greater, this leads to an integer overflow condition. The fix involves using the BIT_ULL macro instead of the standard shift operation to prevent the overflow (NVD).

Impact

The integer overflow vulnerability could potentially affect systems running the Linux kernel with AMD processors. While the specific impact details are not fully disclosed, integer overflow vulnerabilities can lead to incorrect calculations and potentially affect system stability or security (NVD).

Mitigation and workarounds

The vulnerability has been resolved in the Linux kernel by modifying the code to use the BIT_ULL macro instead of direct bit shifting. This change ensures proper 64-bit arithmetic handling and prevents the integer overflow condition (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management