PT-2026-98121 · Linux · Linux Kernel

CVE-2026-97502

·

Published

2026-09-24

·

Updated

2026-09-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference exists in the mmc davinci irq() function within the Linux kernel. The issue occurs because the function only returns early when both host->cmd and host->data are NULL. If host->data is NULL but host->cmd is not, the execution continues to branches handling read data timeouts (TOUTRD) and data CRC errors (CRCWR/CRCRD). These branches dereference the data variable unconditionally, leading to a kernel crash if the corresponding bits are set in qstatus while host->data is NULL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97502

Affected Products

Linux Kernel