SB2025100311 - Improper locking in Linux kernel platform chrome driver
Published: October 3, 2025 Updated: October 27, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2022-50468)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the cros_usbpd_notify_init() function in drivers/platform/chrome/cros_usbpd_notify.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5a2d96623670155d94aca72c320c0ac27bdc6bd2
- https://git.kernel.org/stable/c/5c0cacdd354987f8f5348d16908716f154047890
- https://git.kernel.org/stable/c/751f12696d797e785d2611099fe9f0569d47556e
- https://git.kernel.org/stable/c/7b6ee54995739202b4a0cc01b7e9269f761c573d
- https://git.kernel.org/stable/c/cab345f9d51943898e406275f9607c145adb1877
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.86