CVE-2026-98227

Source
https://cve.org/CVERecord?id=CVE-2026-98227
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98227.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98227
Downstream
Published
2026-10-06T08:45:02Z
Modified
2026-10-07T02:47:30Z
Summary
memstick: ms_block: destroy io_queue workqueue on removal
Details

In the Linux kernel, the following vulnerability has been resolved:

memstick: ms_block: destroy io_queue workqueue on removal

msb_init_disk() creates the per-card ordered workqueue msb->io_queue with alloc_ordered_workqueue(). It is torn down with destroy_workqueue() only on the init error path; msb_remove() never destroys it. msb_stop() merely flushes the queue, and neither msb_data_clear() nor put_disk() free it. As a result every card insert/remove cycle leaks the workqueue and its kworker, exhausting kernel memory over repeated cycles.

Destroy the workqueue in msb_remove() after the disk has been removed and the queue drained.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98227.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0ab30494bc4f3bc1ea4659b7c5d97c5218554a63
Fixed
0ff795163f37109a134b5a421558530f8d091544
Fixed
19c3da6621a253f1f8b937ed91bc22330a930d9c
Fixed
9a2e7cdc0880e735aff0968ee402f2c92a992b9b
Fixed
6611f78ec3fd4b33a00bfda20725b254a22979f6
Fixed
f222bb8c30cf5699c560b29179ff2bddcac1f950
Fixed
90af7fde083e1b22c349c3a8b1626728e44e474c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98227.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.12.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98227.json"