cbcvebase.
CVE-2022-50670
published 2025-12-09

CVE-2022-50670: In the Linux kernel, the following vulnerability has been resolved: mmc: omap_hsmmc: fix return value check of mmc_add_host() mmc_add_host() may return error…

PriorityP421low5.5
EPSS
0.24%
15.2th percentile
In the Linux kernel, the following vulnerability has been resolved: mmc: omap_hsmmc: fix return value check of mmc_add_host() mmc_add_host() may return error, if we ignore its return value, it will lead two issues: 1. The memory that allocated in mmc_alloc_host() is leaked. 2. In the remove() path, mmc_remove_host() will be called to delete device, but it's not added yet, it will lead a kernel crash because of null-ptr-deref in device_del(). Fix this by checking the return value and goto error path wihch will call mmc_free_host().

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= a45c6cb816474cefe56059fce422a9bdcd77e0dc < f153c9e15f8961bdf38707853e15b42ea7c691d9f153c9e15f8961bdf38707853e15b42ea7c691d9
linuxlinux>= a45c6cb816474cefe56059fce422a9bdcd77e0dc < fb3d596267a98813a7a8206097d8d46c98505a0dfb3d596267a98813a7a8206097d8d46c98505a0d
linuxlinux>= a45c6cb816474cefe56059fce422a9bdcd77e0dc < 62005dfcc396424db3337a1dc3ab49623537f5e562005dfcc396424db3337a1dc3ab49623537f5e5
linuxlinux>= a45c6cb816474cefe56059fce422a9bdcd77e0dc < a5f8a4583280a76e50329b910e91ef1dea1e6c79a5f8a4583280a76e50329b910e91ef1dea1e6c79
linuxlinux>= a45c6cb816474cefe56059fce422a9bdcd77e0dc < 4e1dc24bcfc8257f24c0663badec7e4f3ae805584e1dc24bcfc8257f24c0663badec7e4f3ae80558
linuxlinux>= a45c6cb816474cefe56059fce422a9bdcd77e0dc < a525cad241c339ca00bf7ebf03c5180f2a9b767ca525cad241c339ca00bf7ebf03c5180f2a9b767c
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 2.6.29 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11.0 < 5.15.865.15.86
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 5.5.0 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.