Back

HIGH

powercap: intel_rapl: fix UBSAN shift-out-of-bounds issue

Published Sep 17, 2025

Description

When value < time_unit, the parameter of ilog2() will be zero and the return value is -1. u64(-1) is too large for shift exponent and then will trigger shift-out-of-bounds:

shift exponent 18446744073709551615 is too large for 32-bit type 'int' Call Trace: rapl_compute_time_window_core rapl_write_data_raw set_time_window store_constraint_time_window_us

Affected products

Remediation

Red Hat statement

This patch fixes a shift-out-of-bounds bug in the Intel RAPL driver when value < time_unit, which previously caused ilog2(0) to return -1. While not exploitable remotely, a local user with write access to RAPL sysfs controls could trigger a kernel warning or crash.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 17, 2025
Updated May 11, 2026
Reserved Sep 17, 2025
CISA Vulnrichment
Updated Jan 14, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 17, 2025