---
id: CVE-2026-98208
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mmc: sdio_uart: fix xmit_fifo leak when the port table is full

  sdio_uart_add_port() allocates the transmit fifo before claiming a
  slot in sdio_uart_table[]
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mmc: sdio_uart: fix xmit_fifo leak when the port table is full

  sdio_uart_add_port() allocates the transmit fifo before claiming a
  slot in sdio_uart_table[].  When all …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 8b197a5ce7a7218bb9fc721647ba0d5734f27348 <
    9e992d59138fcfaa4bad7cc0750265b0a8bca100
  - >-
    Linux >= 8b197a5ce7a7218bb9fc721647ba0d5734f27348 <
    b97b5b66c93cb4aaf6358727a73fff880a774dfd
  - >-
    Linux >= 8b197a5ce7a7218bb9fc721647ba0d5734f27348 <
    8a2c1bf209ba04cbd14153a771724bd5aa522fcd
  - >-
    Linux >= 8b197a5ce7a7218bb9fc721647ba0d5734f27348 <
    72f4c2b7a48423c708f2c348585419a1b71ab04c
  - >-
    Linux >= 8b197a5ce7a7218bb9fc721647ba0d5734f27348 <
    fd8223c53ad9553b2a349d2a40e19bbc6e60fc48
  - >-
    Linux >= 8b197a5ce7a7218bb9fc721647ba0d5734f27348 <
    ac866db277a4c73e84b4263773652e3aba326249
  - >-
    Linux >= 8b197a5ce7a7218bb9fc721647ba0d5734f27348 <
    5e142adbbdc54afbd01fad476c91cded41d22594
  - >-
    Linux >= 8b197a5ce7a7218bb9fc721647ba0d5734f27348 <
    53823e25793a97d07e6e98e0904bbf74cac8bc76
  - Linux 2.6.34
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:07.017'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98208'
references:
  - url: 'https://git.kernel.org/stable/c/53823e25793a97d07e6e98e0904bbf74cac8bc76'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5e142adbbdc54afbd01fad476c91cded41d22594'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/72f4c2b7a48423c708f2c348585419a1b71ab04c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8a2c1bf209ba04cbd14153a771724bd5aa522fcd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9e992d59138fcfaa4bad7cc0750265b0a8bca100'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ac866db277a4c73e84b4263773652e3aba326249'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b97b5b66c93cb4aaf6358727a73fff880a774dfd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fd8223c53ad9553b2a349d2a40e19bbc6e60fc48'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.444Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

mmc: sdio_uart: fix xmit_fifo leak when the port table is full

sdio_uart_add_port() allocates the transmit fifo before claiming a
slot in sdio_uart_table[].  When all UART_NR slots are taken, it
returns -EBUSY with the fifo still allocated, but the probe error
path only kfree()s the port, leaking the transmit fifo.

Free the fifo in the failure path of sdio_uart_add_port() itself so
the function retains nothing on error.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
