PT-2026-106542 · Linux · Linux
CVE-2026-98213
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
mmc: core: Cancel SDIO IRQ work before freeing host
A host controller that uses sdio signal irq() schedules host->sdio irq work
from its interrupt handler. That work is only cancelled on the suspend
path (mmc sdio suspend()), not on the remove/free path, so a worker armed
just before the controller freed its IRQ can run after
mmc host classdev release() has freed the host and dereference it through
container of().
Cancel host->sdio irq work in mmc free host(), like the existing
host->detect drain added by commit 1036f69e2513 ("mmc: core: Cancel
delayed work before releasing host").
This issue was found by an in-house static analysis tool.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux