{"id":"AZL-106418","summary":"CVE-2026-98212 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: hsq: Fix use-after-free in retry work\n\nmmc_hsq_pump_requests() queues retry_work when request_atomic() returns\n-EBUSY; today sdhci-sprd is the only consumer that implements\nrequest_atomic(). The work is embedded in a devm-allocated mmc_hsq, but\nis never cancelled during driver removal. Work still pending at unbind\ncan therefore run after the devm allocation has been released and\ndereference hsq-\u003emmc and hsq-\u003emrq.\n\nUse devm_work_autocancel() to cancel and drain retry_work before the devm\nallocation is released. By the time devres cleanup begins,\nmmc_remove_host() has already stopped the host, so no new requests can\narm the work.\n\nThis issue was found by an in-house static analysis tool.","modified":"2026-10-07T14:17:03.348448749Z","published":"2026-10-06T09:18:07Z","upstream":["CVE-2026-98212"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98212"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106418.json"}}],"schema_version":"1.9.0"}