cbcvebase.
CVE-2022-50347
published 2025-09-16

CVE-2022-50347: In the Linux kernel, the following vulnerability has been resolved: mmc: rtsx_usb_sdmmc: fix return value check of mmc_add_host() mmc_add_host() may return…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.7th percentile
In the Linux kernel, the following vulnerability has been resolved: mmc: rtsx_usb_sdmmc: fix return value check of mmc_add_host() mmc_add_host() may return error, if we ignore its return value, the memory that allocated in mmc_alloc_host() will be leaked and it will lead a kernel crash because of deleting not added device in the remove path. So fix this by checking the return value and calling mmc_free_host() in the error path, besides, led_classdev_unregister() and pm_runtime_disable() also need be called.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= c7f6558d84afe60016b8103c0737df6e376a1c2d < d7ad7278be401b09c9f9a9f522cf4c449c7fd489d7ad7278be401b09c9f9a9f522cf4c449c7fd489
linuxlinux>= c7f6558d84afe60016b8103c0737df6e376a1c2d < e598c9683fe1cf97c2b11b800cc3cee072108220e598c9683fe1cf97c2b11b800cc3cee072108220
linuxlinux>= c7f6558d84afe60016b8103c0737df6e376a1c2d < 89303ddbb502c3bc8edbf864f9f85500c8fe07e989303ddbb502c3bc8edbf864f9f85500c8fe07e9
linuxlinux>= c7f6558d84afe60016b8103c0737df6e376a1c2d < 937112e991ed25d1727d878734adcbef3b900274937112e991ed25d1727d878734adcbef3b900274
linuxlinux>= c7f6558d84afe60016b8103c0737df6e376a1c2d < 7fa922c7a3dd623fd59f1af50e8896fd9ca7f6547fa922c7a3dd623fd59f1af50e8896fd9ca7f654
linuxlinux>= c7f6558d84afe60016b8103c0737df6e376a1c2d < df683201c7ffbd21a806a7cad657b661c5ebfb6fdf683201c7ffbd21a806a7cad657b661c5ebfb6f
linuxlinux>= c7f6558d84afe60016b8103c0737df6e376a1c2d < 1491667d5450778a265eddddd294219acfd648cb1491667d5450778a265eddddd294219acfd648cb
linuxlinux>= c7f6558d84afe60016b8103c0737df6e376a1c2d < a522e26a20a43dcfbef9ee9f71ed803290e852b0a522e26a20a43dcfbef9ee9f71ed803290e852b0
linuxlinux>= c7f6558d84afe60016b8103c0737df6e376a1c2d < fc38a5a10e9e5a75eb9189854abeb8405b214cc9fc38a5a10e9e5a75eb9189854abeb8405b214cc9
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 3.16 < 4.9.3374.9.337
linuxlinux_kernel>= 4.10 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.