{"id":"DEBIAN-CVE-2022-48755","details":"In the Linux kernel, the following vulnerability has been resolved:  powerpc64/bpf: Limit 'ldbrx' to processors compliant with ISA v2.06  Johan reported the below crash with test_bpf on ppc64 e5500:    test_bpf: #296 ALU_END_FROM_LE 64: 0x0123456789abcdef -\u003e 0x67452301 jited:1   Oops: Exception in kernel mode, sig: 4 [#1]   BE PAGE_SIZE=4K SMP NR_CPUS=24 QEMU e500   Modules linked in: test_bpf(+)   CPU: 0 PID: 76 Comm: insmod Not tainted 5.14.0-03771-g98c2059e008a-dirty #1   NIP:  8000000000061c3c LR: 80000000006dea64 CTR: 8000000000061c18   REGS: c0000000032d3420 TRAP: 0700   Not tainted (5.14.0-03771-g98c2059e008a-dirty)   MSR:  0000000080089000 \u003cEE,ME\u003e  CR: 88002822  XER: 20000000 IRQMASK: 0   \u003c...\u003e   NIP [8000000000061c3c] 0x8000000000061c3c   LR [80000000006dea64] .__run_one+0x104/0x17c [test_bpf]   Call Trace:    .__run_one+0x60/0x17c [test_bpf] (unreliable)    .test_bpf_init+0x6a8/0xdc8 [test_bpf]    .do_one_initcall+0x6c/0x28c    .do_init_module+0x68/0x28c    .load_module+0x2460/0x2abc    .__do_sys_init_module+0x120/0x18c    .system_call_exception+0x110/0x1b8    system_call_common+0xf0/0x210   --- interrupt: c00 at 0x101d0acc   \u003c...\u003e   ---[ end trace 47b2bf19090bb3d0 ]---    Illegal instruction  The illegal instruction turned out to be 'ldbrx' emitted for BPF_FROM_[L|B]E, which was only introduced in ISA v2.06. Guard use of the same and implement an alternative approach for older processors.","modified":"2026-09-01T16:05:29.081823106Z","published":"2024-06-20T12:15:13.653Z","upstream":["CVE-2022-48755"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-48755"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48755.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48755.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48755.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}