CVE-2022-49885: ACPI: APEI: Fix integer overflow in ghes_estatus_pool_init()
In the Linux kernel, the following vulnerability has been resolved:
ACPI: APEI: Fix integer overflow in ghes_estatus_pool_init()
Change num_ghes from int to unsigned int, preventing an overflow
and causing subsequent vmalloc() to fail.
The overflow happens in ghes_estatus_pool_init() when calculating
len during execution of the statement below as both multiplication
operands here are signed int:
len += (num_ghes * GHES_ESOURCE_PREALLOC_MAX_SIZE);
The following call trace is observed because of this bug:
[ 9.317108] swapper/0: vmalloc error: size 18446744071562596352, exceeds total pages, mode:0xcc0(GFP_KERNEL), nodemask=(null),cpuset=/,mems_allowed=0-1
[ 9.317131] Call Trace:
[ 9.317134] <TASK>
[ 9.317137] dump_stack_lvl+0x49/0x5f
[ 9.317145] dump_stack+0x10/0x12
[ 9.317146] warn_alloc.cold+0x7b/0xdf
[ 9.317150] ? __device_attach+0x16a/0x1b0
[ 9.317155] __vmalloc_node_range+0x702/0x740
[ 9.317160] ? device_add+0x17f/0x920
[ 9.317164] ? dev_set_name+0x53/0x70
[ 9.317166] ? platform_device_add+0xf9/0x240
[ 9.317168] __vmalloc_node+0x49/0x50
[ 9.317170] ? ghes_estatus_pool_init+0x43/0xa0
[ 9.317176] vmalloc+0x21/0x30
[ 9.317177] ghes_estatus_pool_init+0x43/0xa0
[ 9.317179] acpi_hest_init+0x129/0x19c
[ 9.317185] acpi_init+0x434/0x4a4
[ 9.317188] ? acpi_sleep_proc_init+0x2a/0x2a
[ 9.317190] do_one_initcall+0x48/0x200
[ 9.317195] kernel_init_freeable+0x221/0x284
[ 9.317200] ? rest_init+0xe0/0xe0
[ 9.317204] kernel_init+0x1a/0x130
[ 9.317205] ret_from_fork+0x22/0x30
[ 9.317208] </TASK>
[ rjw: Subject and changelog edits ]
Security readout for executives and security teams
Plain-English summary
CVE-2022-49885 is a Linux kernel availability bug in ACPI APEI/GHES initialization. An integer overflow can lead to an impossible vmalloc size and allocation failure. The cited record rates it medium, with local low-privilege attack requirements and high availability impact, but no evidence of active exploitation is provided.
Executive priority
Treat as routine but real availability risk. It does not warrant emergency response without additional exploitation evidence, but kernel update programs should include it, especially for shared Linux systems or environments running untrusted local workloads.
Technical view
In ghes_estatus_pool_init(), signed int multiplication of num_ghes and GHES_ESOURCE_PREALLOC_MAX_SIZE can overflow while calculating len. The fix changes num_ghes to unsigned int so the pool sizing calculation avoids overflow and subsequent vmalloc failure. The issue is classified as CWE-190.
Likely exposure
Exposure is limited to systems running affected Linux kernel versions or distro kernels that have not backported the stable fixes. The bundle does not map exposure to specific distributions, appliances, or cloud images.
Exploitation context
The CVSS vector is local, low complexity, low privilege, no user interaction, with availability-only impact. KEV is false, and the supplied sources do not show active exploitation or a practical public trigger path.
Researcher notes
The strongest evidence is the upstream Linux fix and CVSS vector. The source bundle does not explain how an attacker controls num_ghes, so practical exploitability should be validated cautiously against affected hardware, firmware tables, and vendor kernel backports.
Mitigation direction
Update to a Linux kernel containing the referenced stable fixes.
Check vendor or distribution advisories for backported kernel package status.
Prioritize systems where local users can run untrusted workloads.
Track kernel boot or ACPI initialization failures during rollout.
Do not assume distro version numbers match upstream kernel ranges.
Validation and detection
Inventory running kernel versions across Linux hosts.
Compare kernel builds against vendor advisories and referenced stable commits.
Review dmesg for vmalloc failures near ghes_estatus_pool_init or acpi_hest_init.
Confirm patched kernels boot cleanly on ACPI APEI/GHES-capable hardware.
Document any systems requiring vendor-maintained older kernels.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-190: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-190 · source CWE mapping
Integer Overflow or Wraparound
Integer Overflow or Wraparound represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.