{"id":"AZL-106245","summary":"CVE-2026-98210 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mxcmmc: cancel data work and watchdog on remove\n\nmxcmci_remove() frees the host through the devm tail, but neither it nor\nmmc_remove_host() drains the driver's own asynchronous state.\nhost-\u003ewatchdog, a 10 s timer armed on the DMA path in mxcmci_setup_data(),\nis deleted only by the DMA- and IRQ-complete paths, which the remove path\ndoes not explicitly drain; it can therefore fire after the host is freed\nand dereference it in mxcmci_watchdog().  host-\u003edatawork, armed from the\nIRQ handler on the PIO path, is not cancelled by the remove path either.\n\nFree the devm-registered IRQ, then cancel datawork and delete the watchdog\nin mxcmci_remove(), before dma_release_channel().  Freeing the IRQ first\nkeeps a trailing handler from re-arming datawork between the cancel and\nthe host free.  Both callbacks are non-self-rearming.\n\nThis issue was found by an in-house static analysis tool.","modified":"2026-10-07T14:17:00.647397709Z","published":"2026-10-06T09:18:07Z","upstream":["CVE-2026-98210"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98210"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106245.json"}}],"schema_version":"1.9.0"}