CVE-2026-98212

Source
https://cve.org/CVERecord?id=CVE-2026-98212
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98212.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98212
Downstream
Published
2026-10-06T08:44:48Z
Modified
2026-10-08T02:52:53Z
Summary
mmc: hsq: Fix use-after-free in retry work
Details

In the Linux kernel, the following vulnerability has been resolved:

mmc: hsq: Fix use-after-free in retry work

mmc_hsq_pump_requests() queues retry_work when request_atomic() returns -EBUSY; today sdhci-sprd is the only consumer that implements request_atomic(). The work is embedded in a devm-allocated mmc_hsq, but is never cancelled during driver removal. Work still pending at unbind can therefore run after the devm allocation has been released and dereference hsq->mmc and hsq->mrq.

Use devm_work_autocancel() to cancel and drain retry_work before the devm allocation is released. By the time devres cleanup begins, mmc_remove_host() has already stopped the host, so no new requests can arm the work.

This issue was found by an in-house static analysis tool.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98212.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6db96e5810e0a6a345b7d78549de7676ae5b2662
Fixed
c50d6515bffb148c2c12be6d587ec201dfab4c34
Fixed
df2eb59fd9eb33663dc1053f5a4ed851e0aa1f67
Fixed
8439bf262ce3267bcfee29d3c61605f1731a2271
Fixed
45341b341642c377192c95e4d48e0a859cf85f42
Fixed
5d132990475f02cfa1debe03d50b479432864ebd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98212.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.8.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98212.json"