{"id":"CVE-2026-98210","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mxcmmc: cancel data work and watchdog on remove\n\nmxcmci_remove() frees the host through the devm tail, but neither it nor\nmmc_remove_host() drains the driver's own…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mxcmmc: cancel data work and watchdog on remove\n\nmxcmci_remove() frees the host through the devm tail, but neither it nor\nmmc_remove_host() drains the driver's own…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= f6ad0a481342223b2e7ae9f55b154e14f1391ada < 740f595f8ad678cb4d79f13edd12851df2492bdd","Linux >= f6ad0a481342223b2e7ae9f55b154e14f1391ada < d3641afe6ee76d852834a34ef0669eefced32752","Linux >= f6ad0a481342223b2e7ae9f55b154e14f1391ada < 314966b490323bdcfd3162a1398b00e587e0ced4","Linux >= f6ad0a481342223b2e7ae9f55b154e14f1391ada < ae10838a7cdf0e54caa9d0a4f488704fd04e7f01","Linux >= f6ad0a481342223b2e7ae9f55b154e14f1391ada < a1ff367e0dc961d73707add508a95df5c3509bd1","Linux >= f6ad0a481342223b2e7ae9f55b154e14f1391ada < 23383e0578b58ba2dc0730cf9f7806bd66bf859a","Linux >= f6ad0a481342223b2e7ae9f55b154e14f1391ada < e2948c4232209e87c861a680f20f1e3cf8a57fec","Linux >= f6ad0a481342223b2e7ae9f55b154e14f1391ada < d3a421c82412344022982d5b91ba23194a0a6f29","Linux 3.7"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:07.333","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98210","references":[{"url":"https://git.kernel.org/stable/c/23383e0578b58ba2dc0730cf9f7806bd66bf859a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/314966b490323bdcfd3162a1398b00e587e0ced4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/740f595f8ad678cb4d79f13edd12851df2492bdd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1ff367e0dc961d73707add508a95df5c3509bd1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae10838a7cdf0e54caa9d0a4f488704fd04e7f01","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3641afe6ee76d852834a34ef0669eefced32752","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3a421c82412344022982d5b91ba23194a0a6f29","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2948c4232209e87c861a680f20f1e3cf8a57fec","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.444Z","slug":"CVE-2026-98210","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mxcmmc: cancel data work and watchdog on remove\n\nmxcmci_remove() frees the host through the devm tail, but neither it nor\nmmc_remove_host() drains the driver's own asynchronous state.\nhost->watchdog, a 10 s timer armed on the DMA path in mxcmci_setup_data(),\nis deleted only by the DMA- and IRQ-complete paths, which the remove path\ndoes not explicitly drain; it can therefore fire after the host is freed\nand dereference it in mxcmci_watchdog().  host->datawork, armed from the\nIRQ handler on the PIO path, is not cancelled by the remove path either.\n\nFree the devm-registered IRQ, then cancel datawork and delete the watchdog\nin mxcmci_remove(), before dma_release_channel().  Freeing the IRQ first\nkeeps a trailing handler from re-arming datawork between the cancel and\nthe host free.  Both callbacks are non-self-rearming.\n\nThis issue was found by an in-house static analysis tool.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}