{"id":"CVE-2026-98210","summary":"mmc: mxcmmc: cancel data work and watchdog on remove","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mxcmmc: cancel data work and watchdog on remove\n\nmxcmci_remove() frees the host through the devm tail, but neither it nor\nmmc_remove_host() drains the driver's own asynchronous state.\nhost-\u003ewatchdog, a 10 s timer armed on the DMA path in mxcmci_setup_data(),\nis deleted only by the DMA- and IRQ-complete paths, which the remove path\ndoes not explicitly drain; it can therefore fire after the host is freed\nand dereference it in mxcmci_watchdog().  host-\u003edatawork, armed from the\nIRQ handler on the PIO path, is not cancelled by the remove path either.\n\nFree the devm-registered IRQ, then cancel datawork and delete the watchdog\nin mxcmci_remove(), before dma_release_channel().  Freeing the IRQ first\nkeeps a trailing handler from re-arming datawork between the cancel and\nthe host free.  Both callbacks are non-self-rearming.\n\nThis issue was found by an in-house static analysis tool.","modified":"2026-10-07T02:47:29.993770261Z","published":"2026-10-06T08:44:46.788Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98210.json"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/23383e0578b58ba2dc0730cf9f7806bd66bf859a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/314966b490323bdcfd3162a1398b00e587e0ced4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/740f595f8ad678cb4d79f13edd12851df2492bdd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a1ff367e0dc961d73707add508a95df5c3509bd1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ae10838a7cdf0e54caa9d0a4f488704fd04e7f01"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d3641afe6ee76d852834a34ef0669eefced32752"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d3a421c82412344022982d5b91ba23194a0a6f29"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e2948c4232209e87c861a680f20f1e3cf8a57fec"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98210.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98210"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f6ad0a481342223b2e7ae9f55b154e14f1391ada"},{"fixed":"740f595f8ad678cb4d79f13edd12851df2492bdd"},{"fixed":"d3641afe6ee76d852834a34ef0669eefced32752"},{"fixed":"314966b490323bdcfd3162a1398b00e587e0ced4"},{"fixed":"ae10838a7cdf0e54caa9d0a4f488704fd04e7f01"},{"fixed":"a1ff367e0dc961d73707add508a95df5c3509bd1"},{"fixed":"23383e0578b58ba2dc0730cf9f7806bd66bf859a"},{"fixed":"e2948c4232209e87c861a680f20f1e3cf8a57fec"},{"fixed":"d3a421c82412344022982d5b91ba23194a0a6f29"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98210.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.7.0"},{"fixed":"5.10.271"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.222"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.189"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98210.json"}}],"schema_version":"1.9.0"}