SB2025121024 - Memory leak in Linux kernel mailbox driver
Published: December 10, 2025 Updated: December 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-50672)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the zynqmp_ipi_mbox_probe() and zynqmp_ipi_free_mboxes() functions in drivers/mailbox/zynqmp-ipi-mailbox.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3fcf079958c00d83c51e4f250abf2c77fe9cc1b9
- https://git.kernel.org/stable/c/4f05d8e2fb3ab702c2633a74571e1b31cb579985
- https://git.kernel.org/stable/c/a39b4de0804f9fe0ae911b359ffd4afe7d9d933b
- https://git.kernel.org/stable/c/a6792a0cdef0b1c2d77920246283a72537e60e94
- https://git.kernel.org/stable/c/b3a5c76f61e2b380e29dfc6705854ca1ee85501d
- https://git.kernel.org/stable/c/f2d63cefc012cafe1b7651bbf3302f8bcd8bea4a
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.16