CVE-2022-50640
Last modified
CVE-2022-50640 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: mmc: core: Fix kernel panic when remove non-standard SDIO card SDIO tuple is only allocated for standard SDIO card, especially it causes memory corruption issues when the non-standard SDIO card has removed, which is because the card device's reference counter does not increase for it at sdio_init_func(), but all SDIO card device reference counter gets decreased at sdio_release_func().. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: mmc: core: Fix kernel panic when remove non-standard SDIO card SDIO tuple is only allocated for standard SDIO card, especially it causes memory corruption issues when the non-standard SDIO card has removed, which is because the card device's reference counter does not increase for it at sdio_init_func(), but all SDIO card device reference counter gets decreased at sdio_release_func().
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < b8b2965932e702b21e335ff30e1bb550f5a23b6f; >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < b3275dde570b6420106a715bb58a0af041b94d95; >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 1fb79478695d92bab1c120ad3dad05252b02a29d; >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 7a09c64b7da0abdec3919812e3d93ecc44069ed0; >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 8bf037279b5869ae9331c42bb1527d2680ebba96; >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 1e8cd93ae536581562bab4e1d8c5315bbc2548bf; >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 66d461a92f32b6995b630625d350259b6b1f961b; >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 9972e6b404884adae9eec7463e30d9b3c9a70b18 |
| Linux | Linux | 2.6.36 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50640?
How severe is CVE-2022-50640?
How do I fix CVE-2022-50640?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50634In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50635In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50636In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50637In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50638In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50639In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50641In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50642In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50643In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50644In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50645In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50646In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2022-50640?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
