cbcvebase.
CVE-2022-50886
published 2025-12-30

CVE-2022-50886: In the Linux kernel, the following vulnerability has been resolved: mmc: toshsd: fix return value check of mmc_add_host() mmc_add_host() may return error, if…

PriorityP419low3.3
EPSS
0.20%
10.5th percentile
In the Linux kernel, the following vulnerability has been resolved: mmc: toshsd: fix return value check of mmc_add_host() mmc_add_host() may return error, if we ignore its return value, the memory that allocated in mmc_alloc_host() will be leaked and it will lead a kernel crash because of deleting not added device in the remove path. So fix this by checking the return value and goto error path which will call mmc_free_host(), besides, free_irq() also needs be called.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= a5eb8bbd66ccf9f169419f9652544aec771b7c57 < 34ae492f8d172f0bd193c24cad588b35419ea47a34ae492f8d172f0bd193c24cad588b35419ea47a
linuxlinux>= a5eb8bbd66ccf9f169419f9652544aec771b7c57 < 3329e7b7132ca727263fb0ee214cf52cc6dcaaad3329e7b7132ca727263fb0ee214cf52cc6dcaaad
linuxlinux>= a5eb8bbd66ccf9f169419f9652544aec771b7c57 < 4f6cb1c685f9e20a4a9fa565e442f5af4dad70ff4f6cb1c685f9e20a4a9fa565e442f5af4dad70ff
linuxlinux>= a5eb8bbd66ccf9f169419f9652544aec771b7c57 < 3dbb69a0242c31ea4c9eee22b1c41b515fe509a03dbb69a0242c31ea4c9eee22b1c41b515fe509a0
linuxlinux>= a5eb8bbd66ccf9f169419f9652544aec771b7c57 < aabbedcb6c9a72d12d35dc672e83f0c8064d8a61aabbedcb6c9a72d12d35dc672e83f0c8064d8a61
linuxlinux>= a5eb8bbd66ccf9f169419f9652544aec771b7c57 < 6444079767b68b1fbed0e7668081146e80dcb7196444079767b68b1fbed0e7668081146e80dcb719
linuxlinux>= a5eb8bbd66ccf9f169419f9652544aec771b7c57 < 647e370dd0ef7e212d8d014bda748e461eab2e8c647e370dd0ef7e212d8d014bda748e461eab2e8c
linuxlinux>= a5eb8bbd66ccf9f169419f9652544aec771b7c57 < bfd77b194c94aefbde4efc30ddf8607dd9244672bfd77b194c94aefbde4efc30ddf8607dd9244672
linuxlinux>= a5eb8bbd66ccf9f169419f9652544aec771b7c57 < f670744a316ea983113a65313dcd387b5a992444f670744a316ea983113a65313dcd387b5a992444
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 3.19.0 < 4.9.3374.9.337
linuxlinux_kernel>= 4.10.0 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15.0 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11.0 < 5.15.865.15.86
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 5.5.0 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.