Linux Kernel SDIO Card Reference Counter Vulnerability Causes Kernel Panic

Vulnerability

A vulnerability in the Linux kernel's handling of non-standard SDIO cards can lead to memory corruption and a kernel panic. This issue arises because the reference counter for the non-standard SDIO card is not properly managed when the card is removed. The vulnerability affects the Linux kernel stable tree.

Impact

The vulnerability can cause a kernel panic, disrupting system operations and potentially leading to a denial of service.

Reproduction

The vulnerability can be reproduced by using a non-standard SDIO card and removing it from the system. This will trigger a kernel panic due to the improper management of the card's reference counter, causing memory corruption issues.

Remediation

Users can upgrade to the latest version of the Linux kernel stable tree, where this vulnerability has been addressed.

Added: Dec 9, 2025, 2:25 AM
Updated: Dec 9, 2025, 2:25 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.3
remediation
7.7
relevance
1.3
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.