{"id":"DEBIAN-CVE-2022-50151","details":"In the Linux kernel, the following vulnerability has been resolved:  usb: cdns3: fix random warning message when driver load  Warning log: [    4.141392] Unexpected gfp: 0x4 (GFP_DMA32). Fixing up to gfp: 0xa20 (GFP_ATOMIC). Fix your code! [    4.150340] CPU: 1 PID: 175 Comm: 1-0050 Not tainted 5.15.5-00039-g2fd9ae1b568c #20 [    4.158010] Hardware name: Freescale i.MX8QXP MEK (DT) [    4.163155] Call trace: [    4.165600]  dump_backtrace+0x0/0x1b0 [    4.169286]  show_stack+0x18/0x68 [    4.172611]  dump_stack_lvl+0x68/0x84 [    4.176286]  dump_stack+0x18/0x34 [    4.179613]  kmalloc_fix_flags+0x60/0x88 [    4.183550]  new_slab+0x334/0x370 [    4.186878]  ___slab_alloc.part.108+0x4d4/0x748 [    4.191419]  __slab_alloc.isra.109+0x30/0x78 [    4.195702]  kmem_cache_alloc+0x40c/0x420 [    4.199725]  dma_pool_alloc+0xac/0x1f8 [    4.203486]  cdns3_allocate_trb_pool+0xb4/0xd0  pool_alloc_page(struct dma_pool *pool, gfp_t mem_flags) { \t... \tpage = kmalloc(sizeof(*page), mem_flags); \tpage-\u003evaddr = dma_alloc_coherent(pool-\u003edev, pool-\u003eallocation, \t\t\t\t\t &page-\u003edma, mem_flags); \t... }  kmalloc was called with mem_flags, which is passed down in cdns3_allocate_trb_pool() and have GFP_DMA32 flags. kmall_fix_flags() report warning.  GFP_DMA32 is not useful at all. dma_alloc_coherent() will handle DMA memory region correctly by pool-\u003edev. GFP_DMA32 can be removed safely.","modified":"2026-08-27T23:04:31.266555530Z","published":"2025-06-18T11:15:45.190Z","upstream":["CVE-2022-50151"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50151"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.19.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50151.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.19.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50151.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.19.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50151.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}