CVE-2026-31651 PUBLISHED

mmc: vub300: fix NULL-deref on disconnect

Assigner: Linux
Reserved: 09.03.2026 Published: 24.04.2026 Updated: 24.04.2026

In the Linux kernel, the following vulnerability has been resolved:

mmc: vub300: fix NULL-deref on disconnect

Make sure to deregister the controller before dropping the reference to the driver data on disconnect to avoid NULL-pointer dereferences or use-after-free.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 88095e7b473a3d9ec3b9c60429576e9cbd327c89 to 6446516e626ce7c44bdadbcbb3d7677a2c52ce93 (excl.)
  • affected from 88095e7b473a3d9ec3b9c60429576e9cbd327c89 to ba3b9429de94958dc0060d9816a915dd75c34919 (excl.)
  • affected from 88095e7b473a3d9ec3b9c60429576e9cbd327c89 to 517b58e1d067115f80d198feee10192da4c424d0 (excl.)
  • affected from 88095e7b473a3d9ec3b9c60429576e9cbd327c89 to 6468cab1173f44f7a4b7a05ce8abfdfd1ce1557a (excl.)
  • affected from 88095e7b473a3d9ec3b9c60429576e9cbd327c89 to 53f2642d77ab5f1f303388bff5500363c6cf962c (excl.)
  • affected from 88095e7b473a3d9ec3b9c60429576e9cbd327c89 to c83a282615d8f7ba28cebddd54600b419d562d82 (excl.)
  • affected from 88095e7b473a3d9ec3b9c60429576e9cbd327c89 to 8d09e75759cb2afc0732acfb5a14a93c03805a61 (excl.)
  • affected from 88095e7b473a3d9ec3b9c60429576e9cbd327c89 to dff34ef879c5e73298443956a8b391311ba78d57 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.0 is affected
  • unaffected from 0 to 3.0 (excl.)
  • unaffected from 5.10.253 to 5.10.* (incl.)
  • unaffected from 5.15.203 to 5.15.* (incl.)
  • unaffected from 6.1.169 to 6.1.* (incl.)
  • unaffected from 6.6.135 to 6.6.* (incl.)
  • unaffected from 6.12.82 to 6.12.* (incl.)
  • unaffected from 6.18.23 to 6.18.* (incl.)
  • unaffected from 6.19.13 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References