CVE-2022-50640
published 2025-12-09CVE-2022-50640: In the Linux kernel, the following vulnerability has been resolved: mmc: core: Fix kernel panic when remove non-standard SDIO card SDIO tuple is only allocated…
PriorityP421medium5.1
EPSS
0.21%
10.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
mmc: core: Fix kernel panic when remove non-standard SDIO card
SDIO tuple is only allocated for standard SDIO card, especially it causes
memory corruption issues when the non-standard SDIO card has removed, which
is because the card device's reference counter does not increase for it at
sdio_init_func(), but all SDIO card device reference counter gets decreased
at sdio_release_func().
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.7-1 (bookworm) | linux 6.0.7-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < b8b2965932e702b21e335ff30e1bb550f5a23b6f | b8b2965932e702b21e335ff30e1bb550f5a23b6f |
| linux | linux | >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < b3275dde570b6420106a715bb58a0af041b94d95 | b3275dde570b6420106a715bb58a0af041b94d95 |
| linux | linux | >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 1fb79478695d92bab1c120ad3dad05252b02a29d | 1fb79478695d92bab1c120ad3dad05252b02a29d |
| linux | linux | >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 7a09c64b7da0abdec3919812e3d93ecc44069ed0 | 7a09c64b7da0abdec3919812e3d93ecc44069ed0 |
| linux | linux | >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 8bf037279b5869ae9331c42bb1527d2680ebba96 | 8bf037279b5869ae9331c42bb1527d2680ebba96 |
| linux | linux | >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 1e8cd93ae536581562bab4e1d8c5315bbc2548bf | 1e8cd93ae536581562bab4e1d8c5315bbc2548bf |
| linux | linux | >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 66d461a92f32b6995b630625d350259b6b1f961b | 66d461a92f32b6995b630625d350259b6b1f961b |
| linux | linux | >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 9972e6b404884adae9eec7463e30d9b3c9a70b18 | 9972e6b404884adae9eec7463e30d9b3c9a70b18 |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.7-1 | 6.0.7-1 |
| linux | linux_kernel | >= 0 < 6.0.7-1 | 6.0.7-1 |
| linux | linux_kernel | >= 0 < 6.0.7-1 | 6.0.7-1 |
| linux | linux_kernel | >= 2.6.36 < 4.9.332 | 4.9.332 |
| linux | linux_kernel | >= 4.10.0 < 4.14.298 | 4.14.298 |
| linux | linux_kernel | >= 4.15.0 < 4.19.264 | 4.19.264 |
| linux | linux_kernel | >= 4.20.0 < 5.4.223 | 5.4.223 |
| linux | linux_kernel | >= 5.11.0 < 5.15.77 | 5.15.77 |
| linux | linux_kernel | >= 5.16.0 < 6.0.7 | 6.0.7 |
| linux | linux_kernel | >= 5.5.0 < 5.10.153 | 5.10.153 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4w99-c287-2jvj: In the Linux kernel, the following vulnerability has been resolved:
mmc: core: Fix kernel panic when remove non-standard SDIO card
SDIO tuple is onl
ghsa_unreviewed·2025-12-09
CVE-2022-50640 GHSA-4w99-c287-2jvj: In the Linux kernel, the following vulnerability has been resolved:
mmc: core: Fix kernel panic when remove non-standard SDIO card
SDIO tuple is onl
In the Linux kernel, the following vulnerability has been resolved:
mmc: core: Fix kernel panic when remove non-standard SDIO card
SDIO tuple is only allocated for standard SDIO card, especially it causes
memory corruption issues when the non-standard SDIO card has removed, which
is because the card device's reference counter does not increase for it at
sdio_init_func(), but all SDIO card device reference counter gets decreased
at sdio_release_func().
OSV
CVE-2022-50640: In the Linux kernel, the following vulnerability has been resolved: mmc: core: Fix kernel panic when remove non-standard SDIO card SDIO tuple is only
osv·2025-12-09
CVE-2022-50640 CVE-2022-50640: In the Linux kernel, the following vulnerability has been resolved: mmc: core: Fix kernel panic when remove non-standard SDIO card SDIO tuple is only
In the Linux kernel, the following vulnerability has been resolved: mmc: core: Fix kernel panic when remove non-standard SDIO card SDIO tuple is only allocated for standard SDIO card, especially it causes memory corruption issues when the non-standard SDIO card has removed, which is because the card device's reference counter does not increase for it at sdio_init_func(), but all SDIO card device reference counter gets decreased at sdio_release_func().
OSV
mmc: core: Fix kernel panic when remove non-standard SDIO card
osv·2025-12-09
CVE-2022-50640 mmc: core: Fix kernel panic when remove non-standard SDIO card
mmc: core: Fix kernel panic when remove non-standard SDIO card
In the Linux kernel, the following vulnerability has been resolved:
mmc: core: Fix kernel panic when remove non-standard SDIO card
SDIO tuple is only allocated for standard SDIO card, especially it causes
memory corruption issues when the non-standard SDIO card has removed, which
is because the card device's reference counter does not increase for it at
sdio_init_func(), but all SDIO card device reference counter gets decreased
at sdio_release_func().
Red Hat
kernel: mmc: core: Fix kernel panic when remove non-standard SDIO card
vendor_redhat·2025-12-09·CVSS 5.1
CVE-2022-50640 [MEDIUM] CWE-119 kernel: mmc: core: Fix kernel panic when remove non-standard SDIO card
kernel: mmc: core: Fix kernel panic when remove non-standard SDIO card
In the Linux kernel, the following vulnerability has been resolved:
mmc: core: Fix kernel panic when remove non-standard SDIO card
SDIO tuple is only allocated for standard SDIO card, especially it causes
memory corruption issues when the non-standard SDIO card has removed, which
is because the card device's reference counter does not increase for it at
sdio_init_func(), but all SDIO card device reference counter gets decreased
at sdio_release_func().
A flaw in the Linux kernel mmc core driver was discovered that could lead to a kernel panic and memory corruption when a non-standard SDIO card is removed. The Vulnerability arises because SDIO tuples are only allocated for standard SDIO cards, resulting in an inconsiste
Debian
CVE-2022-50640: linux - In the Linux kernel, the following vulnerability has been resolved: mmc: core: ...
vendor_debian·2022
CVE-2022-50640 CVE-2022-50640: linux - In the Linux kernel, the following vulnerability has been resolved: mmc: core: ...
In the Linux kernel, the following vulnerability has been resolved: mmc: core: Fix kernel panic when remove non-standard SDIO card SDIO tuple is only allocated for standard SDIO card, especially it causes memory corruption issues when the non-standard SDIO card has removed, which is because the card device's reference counter does not increase for it at sdio_init_func(), but all SDIO card device reference counter gets decreased at sdio_release_func().
Scope: local
bookworm: resolved (fixed in 6.0.7-1)
bullseye: resolved (fixed in 5.10.158-1)
forky: resolved (fixed in 6.0.7-1)
sid: resolved (fixed in 6.0.7-1)
trixie: resolved (fixed in 6.0.7-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1e8cd93ae536581562bab4e1d8c5315bbc2548bfhttps://git.kernel.org/stable/c/1fb79478695d92bab1c120ad3dad05252b02a29dhttps://git.kernel.org/stable/c/66d461a92f32b6995b630625d350259b6b1f961bhttps://git.kernel.org/stable/c/7a09c64b7da0abdec3919812e3d93ecc44069ed0https://git.kernel.org/stable/c/8bf037279b5869ae9331c42bb1527d2680ebba96https://git.kernel.org/stable/c/9972e6b404884adae9eec7463e30d9b3c9a70b18https://git.kernel.org/stable/c/b3275dde570b6420106a715bb58a0af041b94d95https://git.kernel.org/stable/c/b8b2965932e702b21e335ff30e1bb550f5a23b6f
2025-12-09
Published