{"id":"CVE-2026-98213","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: core: Cancel SDIO IRQ work before freeing host\n\nA host controller that uses sdio_signal_irq() schedules host->sdio_irq_work\nfrom its interrupt handler","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: core: Cancel SDIO IRQ work before freeing host\n\nA host controller that uses sdio_signal_irq() schedules host->sdio_irq_work\nfrom its interrupt handler.  That work …","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 682696605c7093d2800c498c04166831e5aedf87 < bae1cf4f9902b2065bd78b759c7fe6312855f05e","Linux >= 682696605c7093d2800c498c04166831e5aedf87 < 0bf3d168a2cc20b120d6b50f0a8ac5b40ff4d589","Linux >= 682696605c7093d2800c498c04166831e5aedf87 < 1d6e7315ee1c992b4ca42c9b11c5ed0e925a00e0","Linux >= 682696605c7093d2800c498c04166831e5aedf87 < 4553b5004eca9c9eae29a421f1a9c4d5db2c9114","Linux >= 682696605c7093d2800c498c04166831e5aedf87 < 2a863458828ade0671c2bc2e469bbd7f2340eb03","Linux >= 682696605c7093d2800c498c04166831e5aedf87 < 6feadbecdae60a6324c967f3b1493741083793a3","Linux 4.13"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:07.770","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98213","references":[{"url":"https://git.kernel.org/stable/c/0bf3d168a2cc20b120d6b50f0a8ac5b40ff4d589","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1d6e7315ee1c992b4ca42c9b11c5ed0e925a00e0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2a863458828ade0671c2bc2e469bbd7f2340eb03","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4553b5004eca9c9eae29a421f1a9c4d5db2c9114","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6feadbecdae60a6324c967f3b1493741083793a3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bae1cf4f9902b2065bd78b759c7fe6312855f05e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.442Z","slug":"CVE-2026-98213","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmmc: core: Cancel SDIO IRQ work before freeing host\n\nA host controller that uses sdio_signal_irq() schedules host->sdio_irq_work\nfrom its interrupt handler.  That work is only cancelled on the suspend\npath (mmc_sdio_suspend()), not on the remove/free path, so a worker armed\njust before the controller freed its IRQ can run after\nmmc_host_classdev_release() has freed the host and dereference it through\ncontainer_of().\n\nCancel host->sdio_irq_work in mmc_free_host(), like the existing\nhost->detect drain added by commit 1036f69e2513 (\"mmc: core: Cancel\ndelayed work before releasing host\").\n\nThis issue was found by an in-house static analysis tool.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}