CVE-2022-49666: powerpc/memhotplug: Add add_pages override for PPC

Published Feb 26, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

powerpc/memhotplug: Add addpages override for PPC

With commit ffa0b64e3be5 ("powerpc: Fix virtaddrvalid() for 64-bit Book3E & 32-bit") the kernel now validate the addr against highmemory value. This results in the below BUGON with dax pfns.

[ 635.798741][T26531] kernel BUG at mm/pagealloc.c:5521! 1:mon> e cpu 0x1: Vector: 700 (Program Check) at [c000000007287630] pc: c00000000055ed48: freepages.part.0+0x48/0x110 lr: c00000000053ca70: tlbfinishmmu+0x80/0xd0 sp: c0000000072878d0 msr: 800000000282b033 current = 0xc00000000afabe00 paca = 0xc00000037ffff300 irqmask: 0x03 irqhappened: 0x05 pid = 26531, comm = 50-landscape-sy kernel BUG at :5521! Linux version 5.19.0-rc3-14659-g4ec05be7c2e1 (kvaneesh@ltc-boston8) (gcc (Ubuntu 9.4.0-1ubuntu1~20.04.1) 9.4.0, GNU ld (GNU Binutils for Ubuntu) 2.34) #625 SMP Thu Jun 23 00:35:43 CDT 2022 1:mon> t [link register ] c00000000053ca70 tlbfinishmmu+0x80/0xd0 [c0000000072878d0] c00000000053ca54 tlbfinishmmu+0x64/0xd0 (unreliable) [c000000007287900] c000000000539424 exitmmap+0xe4/0x2a0 [c0000000072879e0] c00000000019fc1c mmput+0xcc/0x210 [c000000007287a20] c000000000629230 beginnewexec+0x5e0/0xf40 [c000000007287ae0] c00000000070b3cc loadelfbinary+0x3ac/0x1e00 [c000000007287c10] c000000000627af0 bprmexecve+0x3b0/0xaf0 [c000000007287cd0] c000000000628414 doexecveatcommon.isra.0+0x1e4/0x310 [c000000007287d80] c00000000062858c sysexecve+0x4c/0x60 [c000000007287db0] c00000000002c1b0 systemcallexception+0x160/0x2c0 [c000000007287e10] c00000000000c53c systemcallcommon+0xec/0x250

The fix is to make sure we update highmemory on memory hotplug. This is similar to what x86 does in commit 3072e413e305 ("mm/memoryhotplug: introduce addpages")

Affected Software

18 affected components
Linux Linux kernel
Linux Linux kernel>=5.4.190<5.5
Linux Linux kernel>=5.10.111<5.11
Linux Linux kernel>=5.15.34<5.15.53
Linux Linux kernel>=5.16.20<5.17
Linux Linux kernel>=5.17.3<5.18
Linux Linux kernel>=5.18.1<5.18.10
Linux Linux kernel=5.18
Linux Linux kernel=5.18-rc2
Linux Linux kernel=5.18-rc3
Linux Linux kernel=5.18-rc4
Linux Linux kernel=5.18-rc5
Linux Linux kernel=5.18-rc6
Linux Linux kernel=5.18-rc7
Linux Linux kernel=5.19-rc1
Linux Linux kernel=5.19-rc2
Linux Linux kernel=5.19-rc3
Linux Linux kernel=5.19-rc4

Event History

Feb 26, 2025
CVE Published
via MITRE·02:24 AM
Data Sourced
via MITRE·02:24 AM
Description
Data Sourced
via NVD·07:01 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2022-49666?

The severity of CVE-2022-49666 is classified as important due to its potential impact on system stability.

2

How do I fix CVE-2022-49666?

To fix CVE-2022-49666, upgrade the Linux Kernel to version 5.19.0 or later where the vulnerability has been addressed.

3

What versions of the Linux Kernel are affected by CVE-2022-49666?

CVE-2022-49666 affects Linux Kernel versions prior to 5.19.0.

4

Is my system vulnerable to CVE-2022-49666?

You may be vulnerable to CVE-2022-49666 if you are running a Linux Kernel version older than 5.19.0.

5

What types of systems are impacted by CVE-2022-49666?

CVE-2022-49666 impacts systems using the Linux Kernel on powerpc architecture due to the memory hotplug functionality.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203