LiveActive security incident?Get immediate response
CVE Record

CVE-2022-49964: arm64: cacheinfo: Fix incorrect assignment of signed error value to unsigned fw_level

In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Fix incorrect assignment of signed error value to unsigned fw_level Though acpi_find_last_cache_level() always returned signed value and the document states it will return any errors caused by lack of a PPTT table, it never returned negative values before. Commit 0c80f9e165f8 ("ACPI: PPTT: Leave the table mapped for the runtime usage") however changed it by returning -ENOENT if no PPTT was found. The value returned from acpi_find_last_cache_level() is then assigned to unsigned fw_level. It will result in the number of cache leaves calculated incorrectly as a huge value which will then cause the following warning from __alloc_pages as the order would be great than MAX_ORDER because of incorrect and huge cache leaves value. | WARNING: CPU: 0 PID: 1 at mm/page_alloc.c:5407 __alloc_pages+0x74/0x314 | Modules linked in: | CPU: 0 PID: 1 Comm: swapper/0 Not tainted 5.19.0-10393-g7c2a8d3ac4c0 #73 | pstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) | pc : __alloc_pages+0x74/0x314 | lr : alloc_pages+0xe8/0x318 | Call trace: | __alloc_pages+0x74/0x314 | alloc_pages+0xe8/0x318 | kmalloc_order_trace+0x68/0x1dc | __kmalloc+0x240/0x338 | detect_cache_attributes+0xe0/0x56c | update_siblings_masks+0x38/0x284 | store_cpu_topology+0x78/0x84 | smp_prepare_cpus+0x48/0x134 | kernel_init_freeable+0xc4/0x14c | kernel_init+0x2c/0x1b4 | ret_from_fork+0x10/0x20 Fix the same by changing fw_level to be signed integer and return the error from init_cache_level() early in case of error.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This is a Linux kernel ARM64 bug where an error value can be treated as a very large cache level count. On affected systems, especially without an ACPI PPTT table, it can trigger excessive allocation behavior and kernel warnings during CPU topology setup.

Executive priority

Treat as a targeted kernel reliability issue, not an emergency based on current evidence. Prioritize patching for ARM64 fleets where boot reliability matters, while awaiting vendor-specific severity and package guidance.

Technical view

The ARM64 cacheinfo path assigns acpi_find_last_cache_level() output to unsigned fw_level. After commit 0c80f9e165f8, missing PPTT can return -ENOENT, which becomes a huge unsigned value. The fix makes fw_level signed and returns early on init_cache_level() errors.

Likely exposure

Exposure appears limited to ARM64 Linux kernels containing the regression and missing the referenced stable fixes. Systems with ACPI PPTT absence are specifically implicated. The source bundle does not provide distro package mappings, CVSS, or a complete affected version range.

Exploitation context

No active exploitation is reported in the supplied sources, and the CVE is not marked KEV. The described failure mode is kernel warning and incorrect allocation sizing during boot-time topology/cache detection, not a documented remote attack path.

Researcher notes

The evidence points to a regression introduced when acpi_find_last_cache_level() began returning -ENOENT for missing PPTT. Impact details are narrow in the source: incorrect cache leaf calculation and allocation warning. No exploitability analysis or CVSS is provided.

Mitigation direction

  • Apply kernel or distribution updates that include the referenced stable fixes.
  • Confirm vendor advisories for affected kernel packages and supported backports.
  • Prioritize ARM64 systems, especially platforms without ACPI PPTT tables.
  • Track kernel boot warnings related to cacheinfo or allocation failures.

Validation and detection

  • Inventory ARM64 Linux hosts and their exact kernel builds.
  • Check whether kernels include the referenced stable commits or distro backports.
  • Review boot logs for cacheinfo, topology, or __alloc_pages warnings.
  • Confirm affected systems behave normally after kernel update or vendor fix.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-49964 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
3Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxf03d253ba71994b196f342a7acad448a56812a8c, 0c80f9e165f8f9cca743d7b6cbdb54362da297e0unaffected
LinuxLinux5.19.4unaffected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.