CVE-2022-50640 addresses a kernel panic vulnerability in the Linux kernel's multimedia card (MMC) core. This issue arises when a non-standard SDIO card is removed, leading to memory corruption due to an improperly managed reference counter. While no specific affected products are listed, it impacts systems running vulnerable Linux kernel versions. The vulnerability's severity is not formally rated with a CVSS score, but its potential to cause a kernel panic indicates a denial-of-service impact. The attack vector would likely involve physical access or a compromised system to insert and remove a specially crafted non-standard SDIO card. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. Its EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 2.6.36CNA affecteddefault affected | |
| Linux | Linux | >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 1e8cd93ae536581562bab4e1d8c5315bbc2548bf, >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 1fb79478695d92bab1c120ad3dad05252b02a29d, >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 66d461a92f32b6995b630625d350259b6b1f961b, >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 7a09c64b7da0abdec3919812e3d93ecc44069ed0, >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 8bf037279b5869ae9331c42bb1527d2680ebba96, >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < 9972e6b404884adae9eec7463e30d9b3c9a70b18, >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < b3275dde570b6420106a715bb58a0af041b94d95, >= 6f51be3d37dff73cf8db771df4169f4c2f1cbf66, < b8b2965932e702b21e335ff30e1bb550f5a23b6fCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
No media coverage found for this CVE.