CVE-2026-98210

Source
https://cve.org/CVERecord?id=CVE-2026-98210
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98210.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98210
Downstream
Published
2026-10-06T08:44:46Z
Modified
2026-10-07T02:47:29Z
Summary
mmc: mxcmmc: cancel data work and watchdog on remove
Details

In the Linux kernel, the following vulnerability has been resolved:

mmc: mxcmmc: cancel data work and watchdog on remove

mxcmci_remove() frees the host through the devm tail, but neither it nor mmc_remove_host() drains the driver's own asynchronous state. host->watchdog, a 10 s timer armed on the DMA path in mxcmci_setup_data(), is deleted only by the DMA- and IRQ-complete paths, which the remove path does not explicitly drain; it can therefore fire after the host is freed and dereference it in mxcmci_watchdog(). host->datawork, armed from the IRQ handler on the PIO path, is not cancelled by the remove path either.

Free the devm-registered IRQ, then cancel datawork and delete the watchdog in mxcmci_remove(), before dma_release_channel(). Freeing the IRQ first keeps a trailing handler from re-arming datawork between the cancel and the host free. Both callbacks are non-self-rearming.

This issue was found by an in-house static analysis tool.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98210.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f6ad0a481342223b2e7ae9f55b154e14f1391ada
Fixed
740f595f8ad678cb4d79f13edd12851df2492bdd
Fixed
d3641afe6ee76d852834a34ef0669eefced32752
Fixed
314966b490323bdcfd3162a1398b00e587e0ced4
Fixed
ae10838a7cdf0e54caa9d0a4f488704fd04e7f01
Fixed
a1ff367e0dc961d73707add508a95df5c3509bd1
Fixed
23383e0578b58ba2dc0730cf9f7806bd66bf859a
Fixed
e2948c4232209e87c861a680f20f1e3cf8a57fec
Fixed
d3a421c82412344022982d5b91ba23194a0a6f29

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98210.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.7.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98210.json"