{"id":"CVE-2026-98212","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: hsq: Fix use-after-free in retry work\n\nmmc_hsq_pump_requests() queues retry_work when request_atomic() returns\n-EBUSY; today sdhci-sprd is the only consumer that i…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: hsq: Fix use-after-free in retry work\n\nmmc_hsq_pump_requests() queues retry_work when request_atomic() returns\n-EBUSY; today sdhci-sprd is the only consumer that i…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 6db96e5810e0a6a345b7d78549de7676ae5b2662 < c50d6515bffb148c2c12be6d587ec201dfab4c34","Linux >= 6db96e5810e0a6a345b7d78549de7676ae5b2662 < df2eb59fd9eb33663dc1053f5a4ed851e0aa1f67","Linux >= 6db96e5810e0a6a345b7d78549de7676ae5b2662 < 8439bf262ce3267bcfee29d3c61605f1731a2271","Linux >= 6db96e5810e0a6a345b7d78549de7676ae5b2662 < 45341b341642c377192c95e4d48e0a859cf85f42","Linux >= 6db96e5810e0a6a345b7d78549de7676ae5b2662 < 5d132990475f02cfa1debe03d50b479432864ebd","Linux 5.8"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:07.627","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98212","references":[{"url":"https://git.kernel.org/stable/c/45341b341642c377192c95e4d48e0a859cf85f42","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d132990475f02cfa1debe03d50b479432864ebd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8439bf262ce3267bcfee29d3c61605f1731a2271","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c50d6515bffb148c2c12be6d587ec201dfab4c34","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df2eb59fd9eb33663dc1053f5a4ed851e0aa1f67","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.442Z","slug":"CVE-2026-98212","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmmc: hsq: Fix use-after-free in retry work\n\nmmc_hsq_pump_requests() queues retry_work when request_atomic() returns\n-EBUSY; today sdhci-sprd is the only consumer that implements\nrequest_atomic(). The work is embedded in a devm-allocated mmc_hsq, but\nis never cancelled during driver removal. Work still pending at unbind\ncan therefore run after the devm allocation has been released and\ndereference hsq->mmc and hsq->mrq.\n\nUse devm_work_autocancel() to cancel and drain retry_work before the devm\nallocation is released. By the time devres cleanup begins,\nmmc_remove_host() has already stopped the host, so no new requests can\narm the work.\n\nThis issue was found by an in-house static analysis tool.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}