cbcvebase.
CVE-2022-50858
published 2025-12-30

CVE-2022-50858: In the Linux kernel, the following vulnerability has been resolved: mmc: alcor: fix return value check of mmc_add_host() mmc_add_host() may return error, if we…

PriorityP420low3.3
EPSS
0.21%
11.8th percentile
In the Linux kernel, the following vulnerability has been resolved: mmc: alcor: fix return value check of mmc_add_host() mmc_add_host() may return error, if we ignore its return value, the memory that allocated in mmc_alloc_host() will be leaked and it will lead a kernel crash because of deleting not added device in the remove path. So fix this by checking the return value and calling mmc_free_host() in the error path.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= c5413ad815a675b5c98a002353d8e96b44b164e9 < 289c964fe182ce755044a6cd57698072e12ffa6f289c964fe182ce755044a6cd57698072e12ffa6f
linuxlinux>= c5413ad815a675b5c98a002353d8e96b44b164e9 < 4a6e5d0222804a3eaf2ea4cf893f412e7cf98cb24a6e5d0222804a3eaf2ea4cf893f412e7cf98cb2
linuxlinux>= c5413ad815a675b5c98a002353d8e96b44b164e9 < 29c5b4da41f35108136d843c7432885c78cf827229c5b4da41f35108136d843c7432885c78cf8272
linuxlinux>= c5413ad815a675b5c98a002353d8e96b44b164e9 < 48dc06333d75f41c2ce9ba954bc3231324b4591448dc06333d75f41c2ce9ba954bc3231324b45914
linuxlinux>= c5413ad815a675b5c98a002353d8e96b44b164e9 < 60fafcf2fb7ee9a4125dc9a86eeb9d490acf23e260fafcf2fb7ee9a4125dc9a86eeb9d490acf23e2
linuxlinux>= c5413ad815a675b5c98a002353d8e96b44b164e9 < e93d1468f429475a753d6baa79b853b7ee5ef8c0e93d1468f429475a753d6baa79b853b7ee5ef8c0
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 5.0.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11.0 < 5.15.865.15.86
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 5.5.0 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.