CVE-2026-98208 PUBLISHED

mmc: sdio_uart: fix xmit_fifo leak when the port table is full

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

mmc: sdio_uart: fix xmit_fifo leak when the port table is full

sdio_uart_add_port() allocates the transmit fifo before claiming a slot in sdio_uart_table[]. When all UART_NR slots are taken, it returns -EBUSY with the fifo still allocated, but the probe error path only kfree()s the port, leaking the transmit fifo.

Free the fifo in the failure path of sdio_uart_add_port() itself so the function retains nothing on error.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 8b197a5ce7a7218bb9fc721647ba0d5734f27348 to 9e992d59138fcfaa4bad7cc0750265b0a8bca100 (excl.)
  • affected from 8b197a5ce7a7218bb9fc721647ba0d5734f27348 to b97b5b66c93cb4aaf6358727a73fff880a774dfd (excl.)
  • affected from 8b197a5ce7a7218bb9fc721647ba0d5734f27348 to 8a2c1bf209ba04cbd14153a771724bd5aa522fcd (excl.)
  • affected from 8b197a5ce7a7218bb9fc721647ba0d5734f27348 to 72f4c2b7a48423c708f2c348585419a1b71ab04c (excl.)
  • affected from 8b197a5ce7a7218bb9fc721647ba0d5734f27348 to fd8223c53ad9553b2a349d2a40e19bbc6e60fc48 (excl.)
  • affected from 8b197a5ce7a7218bb9fc721647ba0d5734f27348 to ac866db277a4c73e84b4263773652e3aba326249 (excl.)
  • affected from 8b197a5ce7a7218bb9fc721647ba0d5734f27348 to 5e142adbbdc54afbd01fad476c91cded41d22594 (excl.)
  • affected from 8b197a5ce7a7218bb9fc721647ba0d5734f27348 to 53823e25793a97d07e6e98e0904bbf74cac8bc76 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.34 is affected
  • unaffected from 0 to 2.6.34 (excl.)
  • unaffected from 5.10.271 to 5.10.* (incl.)
  • unaffected from 5.15.222 to 5.15.* (incl.)
  • unaffected from 6.1.189 to 6.1.* (incl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References