CVE-2026-98208

Source
https://cve.org/CVERecord?id=CVE-2026-98208
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98208.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98208
Downstream
Published
2026-10-06T08:44:45Z
Modified
2026-10-08T02:52:53Z
Summary
mmc: sdio_uart: fix xmit_fifo leak when the port table is full
Details

In the Linux kernel, the following vulnerability has been resolved:

mmc: sdio_uart: fix xmit_fifo leak when the port table is full

sdio_uart_add_port() allocates the transmit fifo before claiming a slot in sdio_uart_table[]. When all UART_NR slots are taken, it returns -EBUSY with the fifo still allocated, but the probe error path only kfree()s the port, leaking the transmit fifo.

Free the fifo in the failure path of sdio_uart_add_port() itself so the function retains nothing on error.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98208.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8b197a5ce7a7218bb9fc721647ba0d5734f27348
Fixed
9e992d59138fcfaa4bad7cc0750265b0a8bca100
Fixed
b97b5b66c93cb4aaf6358727a73fff880a774dfd
Fixed
8a2c1bf209ba04cbd14153a771724bd5aa522fcd
Fixed
72f4c2b7a48423c708f2c348585419a1b71ab04c
Fixed
fd8223c53ad9553b2a349d2a40e19bbc6e60fc48
Fixed
ac866db277a4c73e84b4263773652e3aba326249
Fixed
5e142adbbdc54afbd01fad476c91cded41d22594
Fixed
53823e25793a97d07e6e98e0904bbf74cac8bc76

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98208.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.34
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98208.json"