PT-2025-49459 · Linux · Linux Kernel

CVE-2022-50618

·

Published

2022-11-08

·

Updated

2026-02-24

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel where the mmc add host() function's return value is not properly checked. If mmc add host() returns an error, the allocated memory in mmc alloc host() is leaked, and a subsequent call to mmc remove host() in the remove path can cause a kernel crash due to a null-pointer dereference in device del(). The issue occurs because the device is not added correctly, but the removal process attempts to delete it.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unchecked Return Value

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10265
CVE-2022-50618
SUSE-SU-2026:0263-1
SUSE-SU-2026:0317-1
SUSE-SU-2026:0411-1
SUSE-SU-2026:0617-1

Affected Products

Linux Kernel