cbcvebase.
CVE-2022-50640
published 2025-12-09

CVE-2022-50640: In the Linux kernel, the following vulnerability has been resolved: mmc: core: Fix kernel panic when remove non-standard SDIO card SDIO tuple is only allocated…

PriorityP421medium5.1
EPSS
0.21%
10.9th percentile
In the Linux kernel, the following vulnerability has been resolved: mmc: core: Fix kernel panic when remove non-standard SDIO card SDIO tuple is only allocated for standard SDIO card, especially it causes memory corruption issues when the non-standard SDIO card has removed, which is because the card device's reference counter does not increase for it at sdio_init_func(), but all SDIO card device reference counter gets decreased at sdio_release_func().

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.7-1 (bookworm)linux 6.0.7-1 (bookworm)
linuxlinux
linuxlinux>= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < b8b2965932e702b21e335ff30e1bb550f5a23b6fb8b2965932e702b21e335ff30e1bb550f5a23b6f
linuxlinux>= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < b3275dde570b6420106a715bb58a0af041b94d95b3275dde570b6420106a715bb58a0af041b94d95
linuxlinux>= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 1fb79478695d92bab1c120ad3dad05252b02a29d1fb79478695d92bab1c120ad3dad05252b02a29d
linuxlinux>= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 7a09c64b7da0abdec3919812e3d93ecc44069ed07a09c64b7da0abdec3919812e3d93ecc44069ed0
linuxlinux>= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 8bf037279b5869ae9331c42bb1527d2680ebba968bf037279b5869ae9331c42bb1527d2680ebba96
linuxlinux>= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 1e8cd93ae536581562bab4e1d8c5315bbc2548bf1e8cd93ae536581562bab4e1d8c5315bbc2548bf
linuxlinux>= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 66d461a92f32b6995b630625d350259b6b1f961b66d461a92f32b6995b630625d350259b6b1f961b
linuxlinux>= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66 < 9972e6b404884adae9eec7463e30d9b3c9a70b189972e6b404884adae9eec7463e30d9b3c9a70b18
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 2.6.36 < 4.9.3324.9.332
linuxlinux_kernel>= 4.10.0 < 4.14.2984.14.298
linuxlinux_kernel>= 4.15.0 < 4.19.2644.19.264
linuxlinux_kernel>= 4.20.0 < 5.4.2235.4.223
linuxlinux_kernel>= 5.11.0 < 5.15.775.15.77
linuxlinux_kernel>= 5.16.0 < 6.0.76.0.7
linuxlinux_kernel>= 5.5.0 < 5.10.1535.10.153
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.