SB2025121048 - Memory leak in Linux kernel scsi driver
Published: December 10, 2025 Updated: December 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-50646)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the hpsa_init_one() function in drivers/scsi/hpsa.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0aa7be66168b1e84b2581ffff3ccb54a6c804a1e
- https://git.kernel.org/stable/c/9c9ff300e0de07475796495d86f449340d454a0c
- https://git.kernel.org/stable/c/bfe10a1d9fbccdf39f8449d62509f070d8aaaac1
- https://git.kernel.org/stable/c/c808edbf580bfc454671cbe66e9d7c2e938e7601
- https://git.kernel.org/stable/c/f4d1c14e8b404766ff2bb8644bb19443d73965de
- https://git.kernel.org/stable/c/f8fc2f18652917cdcc89cb23f3a1b7cb6e119c5e
- https://git.kernel.org/stable/c/fc998d0a7d65672f0812f11cd0ec4bbe4f8f8507
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.16