---
id: CVE-2026-98212
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mmc: hsq: Fix use-after-free in retry work

  mmc_hsq_pump_requests() queues retry_work when request_atomic() returns
  -EBUSY; today sdhci-sprd is the only consumer that i…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mmc: hsq: Fix use-after-free in retry work

  mmc_hsq_pump_requests() queues retry_work when request_atomic() returns
  -EBUSY; today sdhci-sprd is the only consumer that i…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 6db96e5810e0a6a345b7d78549de7676ae5b2662 <
    c50d6515bffb148c2c12be6d587ec201dfab4c34
  - >-
    Linux >= 6db96e5810e0a6a345b7d78549de7676ae5b2662 <
    df2eb59fd9eb33663dc1053f5a4ed851e0aa1f67
  - >-
    Linux >= 6db96e5810e0a6a345b7d78549de7676ae5b2662 <
    8439bf262ce3267bcfee29d3c61605f1731a2271
  - >-
    Linux >= 6db96e5810e0a6a345b7d78549de7676ae5b2662 <
    45341b341642c377192c95e4d48e0a859cf85f42
  - >-
    Linux >= 6db96e5810e0a6a345b7d78549de7676ae5b2662 <
    5d132990475f02cfa1debe03d50b479432864ebd
  - Linux 5.8
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:07.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98212'
references:
  - url: 'https://git.kernel.org/stable/c/45341b341642c377192c95e4d48e0a859cf85f42'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5d132990475f02cfa1debe03d50b479432864ebd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8439bf262ce3267bcfee29d3c61605f1731a2271'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c50d6515bffb148c2c12be6d587ec201dfab4c34'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/df2eb59fd9eb33663dc1053f5a4ed851e0aa1f67'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.442Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

mmc: hsq: Fix use-after-free in retry work

mmc_hsq_pump_requests() queues retry_work when request_atomic() returns
-EBUSY; today sdhci-sprd is the only consumer that implements
request_atomic(). The work is embedded in a devm-allocated mmc_hsq, but
is never cancelled during driver removal. Work still pending at unbind
can therefore run after the devm allocation has been released and
dereference hsq->mmc and hsq->mrq.

Use devm_work_autocancel() to cancel and drain retry_work before the devm
allocation is released. By the time devres cleanup begins,
mmc_remove_host() has already stopped the host, so no new requests can
arm the work.

This issue was found by an in-house static analysis tool.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
