cpufreq: qcom: fix writes in read-only memory region
Published Sep 15, 2025
7.1
HIGHCVSS 3.1
EPSS 0.16%
Description
This commit fixes a kernel oops because of a write in some read-only memory:
[ 9.068287] Unable to handle kernel write to read-only memory at virtual address ffff800009240ad8 ..snip.. [ 9.138790] Internal error: Oops: 9600004f [#1] PREEMPT SMP ..snip.. [ 9.269161] Call trace: [ 9.276271] __memcpy+0x5c/0x230 [ 9.278531] snprintf+0x58/0x80 [ 9.282002] qcom_cpufreq_msm8939_name_version+0xb4/0x190 [ 9.284869] qcom_cpufreq_probe+0xc8/0x39c ..snip..
The following line defines a pointer that point to a char buffer stored in read-only memory:
char *pvs_name = "speedXX-pvsXX-vXX";
This pointer is meant to hold a template "speedXX-pvsXX-vXX" where the XX values get overridden by the qcom_cpufreq_krait_name_version function. Since the template is actually stored in read-only memory, when the function executes the following call we get an oops:
snprintf(*pvs_name, sizeof("speedXX-pvsXX-vXX"), "speed%d-pvs%d-v%d", speed, pvs, pvs_ver);
To fix this issue, we instead store the template name onto the stack by using the following syntax:
char pvs_name_buffer[] = "speedXX-pvsXX-vXX";
Because the `pvs_name` needs to be able to be assigned to NULL, the template buffer is stored in the pvs_name_buffer and not under the pvs_name variable.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.7StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.7
- Version 5.10.152StatusunaffectedConstraints<=5.10.*
- Version 5.15.76StatusunaffectedConstraints<=5.15.*
- Version 6.0.6StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.7 · < 5.10.152
- ≥ 5.11 · < 5.15.76
- ≥ 5.16 · < 6.0.6
- 6.1
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-50239 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2395336 Issue Tracking
- https://git.kernel.org/stable/c/01039fb8e90c9cb684430414bff70cea9eb168c5 Patch
- https://git.kernel.org/stable/c/14d260f94ff89543597ffea13db8b277a810e08e Patch
- https://git.kernel.org/stable/c/794ded0bc461287a268bed21fea2eebb6e5d232c Patch
- https://git.kernel.org/stable/c/b74ee4e301ca01e431e240c046173332966e2431 Patch
- https://lore.kernel.org/linux-cve-announce/2025091547-CVE-2022-50239-3908@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-50239
- https://www.cve.org/CVERecord?id=CVE-2022-50239
Change history (0)
No recorded changes yet.