PT-2026-106541 · Linux · Linux

CVE-2026-98212

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
mmc: hsq: Fix use-after-free in retry work
mmc hsq pump requests() queues retry work when request atomic() returns -EBUSY; today sdhci-sprd is the only consumer that implements request atomic(). The work is embedded in a devm-allocated mmc hsq, but is never cancelled during driver removal. Work still pending at unbind can therefore run after the devm allocation has been released and dereference hsq->mmc and hsq->mrq.
Use devm work autocancel() to cancel and drain retry work before the devm allocation is released. By the time devres cleanup begins, mmc remove host() has already stopped the host, so no new requests can arm the work.
This issue was found by an in-house static analysis tool.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98212

Affected Products

Linux