SB2025091676 - Memory leak in Linux kernel mmc host driver
Published: September 16, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-50267)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the rtsx_pci_sdmmc_drv_probe() function in drivers/mmc/host/rtsx_pci_sdmmc.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0c87db77423a282b3b38b8a6daf057b822680516
- https://git.kernel.org/stable/c/30dc645461dfc63e52b3af8ee4a98e17bf14bacf
- https://git.kernel.org/stable/c/5cd4e04eccaec140da6fa04db056a76282ee6852
- https://git.kernel.org/stable/c/ffa9b2a79e3e959683efbad3f6db937eca9d38f5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.2