SB2025091697 - Memory leak in Linux kernel mmc host driver
Published: September 16, 2025 Updated: September 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-50251)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the vub300_probe() function in drivers/mmc/host/vub300.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0613ad2401f88bdeae5594c30afe318e93b14676
- https://git.kernel.org/stable/c/2044b2ea77945f372ef161d1bbf814e471767ff2
- https://git.kernel.org/stable/c/25f05d762ca5e1c685002a53dd44f68e78ca3feb
- https://git.kernel.org/stable/c/3049a3b927a40d89d4582ff1033cd7953be773c7
- https://git.kernel.org/stable/c/3b29f8769d32016b2d89183db4d80c7a71b7e35e
- https://git.kernel.org/stable/c/41ed46bdbd2878cd6567abe0974a445f8b1b8ec8
- https://git.kernel.org/stable/c/a46e681151bbdacdf6b89ee8c4e5bad0555142bb
- https://git.kernel.org/stable/c/afc898019e7bf18c5eb7a0ac19852fcb1b341b3c
- https://git.kernel.org/stable/c/c9e85979b59cb86f0a15defa8199d740e2b36b90
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.16