CVE-2022-50640: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: mmc: core: Fix kernel panic when remove non-standard SDIO card SDIO tuple is only allocated for standard SDIO card, especially it causes memory corruption issues when the non-standard SDIO card has removed, which is because the card device's reference counter does not increase for it at sdio_init_func(), but all SDIO card device reference counter gets decreased at sdio_release_func().

Affected products

  • Linux Linux: from 2.6.36, before 4.9.332 (fixed in 4.9.332); from 4.10, before 4.14.298 (fixed in 4.14.298); from 4.15, before 4.19.264 (fixed in 4.19.264); from 4.20, before 5.4.223 (fixed in 5.4.223); from 5.5, before 5.10.153 (fixed in 5.10.153); from 5.11, before 5.15.77 (fixed in 5.15.77); …

Published 2025-12-09. Last modified 2026-06-17.