{"id":"CVE-2026-31651","title":"mmc: vub300: fix NULL-deref on disconnect","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: vub300: fix NULL-deref on disconnect\n\nMake sure to deregister the controller before dropping the reference to\nthe driver data on disconnect to avoid NULL-pointer d…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 6446516e626ce7c44bdadbcbb3d7677a2c52ce93","Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < ba3b9429de94958dc0060d9816a915dd75c34919","Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 517b58e1d067115f80d198feee10192da4c424d0","Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 6468cab1173f44f7a4b7a05ce8abfdfd1ce1557a","Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 53f2642d77ab5f1f303388bff5500363c6cf962c","Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < c83a282615d8f7ba28cebddd54600b419d562d82","Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 8d09e75759cb2afc0732acfb5a14a93c03805a61","Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < dff34ef879c5e73298443956a8b391311ba78d57","Linux 3.0"],"published":"2026-04-24","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:47:52.726Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-31651","references":[{"url":"https://git.kernel.org/stable/c/6446516e626ce7c44bdadbcbb3d7677a2c52ce93"},{"url":"https://git.kernel.org/stable/c/ba3b9429de94958dc0060d9816a915dd75c34919"},{"url":"https://git.kernel.org/stable/c/517b58e1d067115f80d198feee10192da4c424d0"},{"url":"https://git.kernel.org/stable/c/6468cab1173f44f7a4b7a05ce8abfdfd1ce1557a"},{"url":"https://git.kernel.org/stable/c/53f2642d77ab5f1f303388bff5500363c6cf962c"},{"url":"https://git.kernel.org/stable/c/c83a282615d8f7ba28cebddd54600b419d562d82"},{"url":"https://git.kernel.org/stable/c/8d09e75759cb2afc0732acfb5a14a93c03805a61"},{"url":"https://git.kernel.org/stable/c/dff34ef879c5e73298443956a8b391311ba78d57"}],"tags":["cve.org"],"epss":0.00166,"epssPercentile":0.05154,"ingestedAt":"2026-09-08T15:33:26.990Z","slug":"CVE-2026-31651","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmmc: vub300: fix NULL-deref on disconnect\n\nMake sure to deregister the controller before dropping the reference to\nthe driver data on disconnect to avoid NULL-pointer dereferences or\nuse-after-free.\n\n## Affected\n\n- `Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 6446516e626ce7c44bdadbcbb3d7677a2c52ce93`\n- `Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < ba3b9429de94958dc0060d9816a915dd75c34919`\n- `Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 517b58e1d067115f80d198feee10192da4c424d0`\n- `Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 6468cab1173f44f7a4b7a05ce8abfdfd1ce1557a`\n- `Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 53f2642d77ab5f1f303388bff5500363c6cf962c`\n- `Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < c83a282615d8f7ba28cebddd54600b419d562d82`\n- `Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < 8d09e75759cb2afc0732acfb5a14a93c03805a61`\n- `Linux >= 88095e7b473a3d9ec3b9c60429576e9cbd327c89 < dff34ef879c5e73298443956a8b391311ba78d57`\n- `Linux 3.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}