cbcvebase.
CVE-2022-50430
published 2025-10-01

CVE-2022-50430: In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix warning - do not call blocking ops when !TASK_RUNNING…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix warning - do not call blocking ops when !TASK_RUNNING vub300_enable_sdio_irq() works with mutex and need TASK_RUNNING here. Ensure that we mark current as TASK_RUNNING for sleepable context. [ 77.554641] do not call blocking ops when !TASK_RUNNING; state=1 set at [] sdio_irq_thread+0x17d/0x5b0 [ 77.554652] WARNING: CPU: 2 PID: 1983 at kernel/sched/core.c:9813 __might_sleep+0x116/0x160 [ 77.554905] CPU: 2 PID: 1983 Comm: ksdioirqd/mmc1 Tainted: G OE 6.1.0-rc5 #1 [ 77.554910] Hardware name: Intel(R) Client Systems NUC8i7BEH/NUC8BEB, BIOS BECFL357.86A.0081.2020.0504.1834 05/04/2020 [ 77.554912] RIP: 0010:__might_sleep+0x116/0x160 [ 77.554920] RSP: 0018:ffff888107b7fdb8 EFLAGS: 00010282 [ 77.554923] RAX: 0000000000000000 RBX: ffff888118c1b740 RCX: 0000000000000000 [ 77.554926] RDX: 0000000000000001 RSI: 0000000000000004 RDI: ffffed1020f6ffa9 [ 77.554928] RBP: ffff888107b7fde0 R08: 0000000000000001 R09: ffffed1043ea60ba [ 77.554930] R10: ffff88821f5305cb R11: ffffed1043ea60b9 R12: ffffffff93aa3a60 [ 77.554932] R13: 000000000000011b R14: 7fffffffffffffff R15: ffffffffc0558660 [ 77.554934] FS: 0000000000000000(0000) GS:ffff88821f500000(0000) knlGS:0000000000000000 [ 77.554937] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 77.554939] CR2: 00007f8a44010d68 CR3: 000000024421a003 CR4: 00000000003706e0 [ 77.554942] Call Trace: [ 77.554944] [ 77.554952] mutex_lock+0x78/0xf0 [ 77.554973] vub300_enable_sdio_irq+0x103/0x3c0 [vub300] [ 77.554981] sdio_irq_thread+0x25c/0x5b0 [ 77.555006] kthread+0x2b8/0x370 [ 77.555017] ret_from_fork+0x1f/0x30 [ 77.555023] [ 77.555025] ---[ end trace 0000000000000000 ]---

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 32d5af247d4de6a35769ca1d027480a37c28fd0c32d5af247d4de6a35769ca1d027480a37c28fd0c
linuxlinux>= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 48e91ae755f027d817ed7e51db9963ddb708194648e91ae755f027d817ed7e51db9963ddb7081946
linuxlinux>= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 6f7258c6f66692b3760c37ddd4bc9e02bb290da76f7258c6f66692b3760c37ddd4bc9e02bb290da7
linuxlinux>= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < f1c08947ab0538b07a0bd9d6edadfb5185f56344f1c08947ab0538b07a0bd9d6edadfb5185f56344
linuxlinux>= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < b51d5fed9f53e07ce9fc65efb4ff1abe021a4c16b51d5fed9f53e07ce9fc65efb4ff1abe021a4c16
linuxlinux>= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < d58289fc77f8c1f879c818bddaf7ef524c73658bd58289fc77f8c1f879c818bddaf7ef524c73658b
linuxlinux>= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < d15946ef98f4ccdca961b76f90d9b53c454d590ed15946ef98f4ccdca961b76f90d9b53c454d590e
linuxlinux>= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < ba2e7d07dd06e646a72ba906a89fdc1cca7ea560ba2e7d07dd06e646a72ba906a89fdc1cca7ea560
linuxlinux>= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 4a44cd249604e29e7b90ae796d7692f5773dd3484a44cd249604e29e7b90ae796d7692f5773dd348
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 3.0 < 4.9.3374.9.337
linuxlinux_kernel>= 4.10 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.875.15.87
linuxlinux_kernel>= 5.16 < 6.0.176.0.17
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.36.1.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.