CVE-2022-49451: firmware: arm_scmi: Fix list protocols enumeration in the base protocol
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_scmi: Fix list protocols enumeration in the base protocol
While enumerating protocols implemented by the SCMI platform using
BASE_DISCOVER_LIST_PROTOCOLS, the number of returned protocols is
currently validated in an improper way since the check employs a sum
between unsigned integers that could overflow and cause the check itself
to be silently bypassed if the returned value 'loop_num_ret' is big
enough.
Fix the validation avoiding the addition.
Security readout for executives and security teams
Plain-English summary
This is a Linux kernel flaw in ARM SCMI firmware protocol discovery. A local user with low privileges could trigger an availability impact if the platform returns an oversized protocol count. The practical concern is denial of service on affected ARM-based Linux systems, not data theft or remote compromise.
Executive priority
Treat as a moderate operational reliability issue. Prioritize patching shared ARM Linux platforms, edge devices, and multi-tenant systems where local users or workloads could trigger a denial of service.
Technical view
The ARM SCMI base protocol enumeration used unsigned addition while validating returned protocol counts. A large loop_num_ret value could overflow the check and bypass validation. The CVE maps this to CWE-190 with CVSS 5.5: local attack vector, low complexity, low privileges, no confidentiality or integrity impact, and high availability impact.
Likely exposure
Exposure is most relevant to Linux systems using the ARM SCMI firmware driver. The source lists Linux kernel versions including 4.17, 4.19.247, 5.4.198, 5.10.121, 5.15.46, 5.17.14, 5.18.3, and 5.19. Distro backports may change exact status.
Exploitation context
The CVE is not listed as KEV in the supplied data, and no provided source claims active exploitation. The CVSS vector requires local access and low privileges. The supported impact is availability loss only; the bundle does not show remote exploitation, data exposure, or privilege escalation.
Researcher notes
Validation should focus on kernel source lineage and distro backports, because the CVE bundle lists upstream stable commits but not downstream package names. Avoid assuming exposure on non-ARM systems or systems not using SCMI firmware paths.
Mitigation direction
Identify ARM Linux assets using the SCMI firmware driver.
Update kernels using vendor or Linux stable guidance for this CVE.
Confirm distro kernel backports before relying on upstream version numbers.
Prioritize systems where local users or workloads are untrusted.
Validation and detection
Inventory kernel versions on ARM-based Linux hosts.
Check vendor advisories or changelogs for CVE-2022-49451 coverage.
Verify whether ARM SCMI firmware support is enabled or in use.
Confirm patched stable commits are present in deployed kernel sources.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-190: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-190 · source CWE mapping
Integer Overflow or Wraparound
Integer Overflow or Wraparound represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.