VYPR
High severity7.8NVD Advisory· Published Jun 18, 2025· Updated Aug 4, 2026

CVE-2022-50167

CVE-2022-50167

Description

In the Linux kernel, the following vulnerability has been resolved:

bpf: fix potential 32-bit overflow when accessing ARRAY map element

If BPF array map is bigger than 4GB, element pointer calculation can overflow because both index and elem_size are u32. Fix this everywhere by forcing 64-bit multiplication. Extract this formula into separate small helper and use it consistently in various places.

Speculative-preventing formula utilizing index_mask trick is left as is, but explicit u64 casts are added in both places.

Affected products

4
  • Linux/Kernel3 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.3,<5.18.18
    • (no CPE)
    • (no CPE)range: 5.3
  • osv-coords
    Range: >= 5.3.0, < 5.18.18

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.