CVE-2026-98210
Received Received - Intake

Use-After-Free in Linux Kernel MMC Driver

Vulnerability report for CVE-2026-98210, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: mmc: mxcmmc: cancel data work and watchdog on remove mxcmci_remove() frees the host through the devm tail, but neither it nor mmc_remove_host() drains the driver's own asynchronous state. host->watchdog, a 10 s timer armed on the DMA path in mxcmci_setup_data(), is deleted only by the DMA- and IRQ-complete paths, which the remove path does not explicitly drain; it can therefore fire after the host is freed and dereference it in mxcmci_watchdog(). host->datawork, armed from the IRQ handler on the PIO path, is not cancelled by the remove path either. Free the devm-registered IRQ, then cancel datawork and delete the watchdog in mxcmci_remove(), before dma_release_channel(). Freeing the IRQ first keeps a trailing handler from re-arming datawork between the cancel and the host free. Both callbacks are non-self-rearming. This issue was found by an in-house static analysis tool.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux f6ad0a481342223b2e7ae9f55b154e14f1391ada
Linux Linux f6ad0a481342223b2e7ae9f55b154e14f1391ada
Linux Linux f6ad0a481342223b2e7ae9f55b154e14f1391ada
Linux Linux f6ad0a481342223b2e7ae9f55b154e14f1391ada
Linux Linux f6ad0a481342223b2e7ae9f55b154e14f1391ada
Linux Linux f6ad0a481342223b2e7ae9f55b154e14f1391ada
Linux Linux f6ad0a481342223b2e7ae9f55b154e14f1391ada
Linux Linux f6ad0a481342223b2e7ae9f55b154e14f1391ada
Linux Linux 3.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper cleanup during device removal in the mxcmmc driver. When the device is removed, the host structure is freed but asynchronous operations like the watchdog timer and data work are not properly canceled. This can lead to a use-after-free scenario where the watchdog timer fires after the host is freed and tries to access it.

Detection Guidance

This vulnerability is specific to the Linux kernel's mmc subsystem, particularly the mxcmmc driver. Detection requires checking if the affected driver is loaded and examining kernel logs for related errors. No direct network detection commands are applicable. Check kernel messages with 'dmesg | grep mxcmmc' or verify the driver status with 'lsmod | grep mxcmmc'.

Impact Analysis

This vulnerability could cause system instability or crashes due to use-after-free errors. If exploited, it might lead to privilege escalation or denial of service on affected systems running the vulnerable Linux kernel.

Mitigation Strategies

Update the Linux kernel to a patched version where this issue is resolved. If using a custom or vendor kernel, apply the patch manually. No immediate workaround is suggested beyond updating, as the fix involves kernel code changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98210. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart