{"id":"CVE-2026-98212","summary":"mmc: hsq: Fix use-after-free in retry work","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: hsq: Fix use-after-free in retry work\n\nmmc_hsq_pump_requests() queues retry_work when request_atomic() returns\n-EBUSY; today sdhci-sprd is the only consumer that implements\nrequest_atomic(). The work is embedded in a devm-allocated mmc_hsq, but\nis never cancelled during driver removal. Work still pending at unbind\ncan therefore run after the devm allocation has been released and\ndereference hsq-\u003emmc and hsq-\u003emrq.\n\nUse devm_work_autocancel() to cancel and drain retry_work before the devm\nallocation is released. By the time devres cleanup begins,\nmmc_remove_host() has already stopped the host, so no new requests can\narm the work.\n\nThis issue was found by an in-house static analysis tool.","modified":"2026-10-08T02:52:53.381891539Z","published":"2026-10-06T08:44:48.498Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98212.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/45341b341642c377192c95e4d48e0a859cf85f42"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5d132990475f02cfa1debe03d50b479432864ebd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8439bf262ce3267bcfee29d3c61605f1731a2271"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c50d6515bffb148c2c12be6d587ec201dfab4c34"},{"type":"WEB","url":"https://git.kernel.org/stable/c/df2eb59fd9eb33663dc1053f5a4ed851e0aa1f67"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98212.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98212"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6db96e5810e0a6a345b7d78549de7676ae5b2662"},{"fixed":"c50d6515bffb148c2c12be6d587ec201dfab4c34"},{"fixed":"df2eb59fd9eb33663dc1053f5a4ed851e0aa1f67"},{"fixed":"8439bf262ce3267bcfee29d3c61605f1731a2271"},{"fixed":"45341b341642c377192c95e4d48e0a859cf85f42"},{"fixed":"5d132990475f02cfa1debe03d50b479432864ebd"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98212.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.8.0"},{"fixed":"6.6.158"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.112"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98212.json"}}],"schema_version":"1.9.0"}