UBUNTU-CVE-2022-50580
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-50580
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: blk-throttle: prevent overflow while calculating wait time There is a problem found by code review in tg_with_in_bps_limit() that 'bps_limit * jiffy_elapsed_rnd' might overflow. Fix the problem by calling mul_u64_u64_div_u64() instead.
References: https://ubuntu.com/security/CVE-2022-50580, https://www.cve.org/CVERecord?id=CVE-2022-50580, https://git.kernel.org/linus/8d6bbaada2e0a65f9012ac4c2506460160e7237a, https://git.kernel.org/stable/c/19c010ae44f0ce52b5436080492a61a092ee0cf4, https://git.kernel.org/stable/c/70b2adb1d698fbc63d3b3848c452524dc15872c5, https://git.kernel.org/stable/c/8d6bbaada2e0a65f9012ac4c2506460160e7237a, https://git.kernel.org/stable/c/ca67b0563b39e79290c23e509319c178b9ca9104, https://git.kernel.org/stable/c/cc6f0855bf8d9b729df28ff443ced7350c380dbd
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
