SB2025061975 - Memory leak in Linux kernel usb renesas_usbhs driver
Published: June 19, 2025 Updated: June 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-50032)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the usbhs_rza1_hardware_init() function in drivers/usb/renesas_usbhs/rza.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/36b18b777dece704b7c2e9e7947ca41a9b0fb009
- https://git.kernel.org/stable/c/5c4b699193eba51f1bbf462d758d66f545fddd35
- https://git.kernel.org/stable/c/9790a5a4f07f38a5add85ec58c44797d3a7c3677
- https://git.kernel.org/stable/c/9d6d5303c39b8bc182475b22f45504106a07f086
- https://git.kernel.org/stable/c/cfa8f707a58d68b2341a9dd0b33cf048f0628b4d
- https://git.kernel.org/stable/c/fbdbd61a36d887e00114321c6758e359e9573a8e
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.63