CVE-2026-98212 PUBLISHED

mmc: hsq: Fix use-after-free in retry work

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

mmc: hsq: Fix use-after-free in retry work

mmc_hsq_pump_requests() queues retry_work when request_atomic() returns -EBUSY; today sdhci-sprd is the only consumer that implements request_atomic(). The work is embedded in a devm-allocated mmc_hsq, but is never cancelled during driver removal. Work still pending at unbind can therefore run after the devm allocation has been released and dereference hsq->mmc and hsq->mrq.

Use devm_work_autocancel() to cancel and drain retry_work before the devm allocation is released. By the time devres cleanup begins, mmc_remove_host() has already stopped the host, so no new requests can arm the work.

This issue was found by an in-house static analysis tool.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 6db96e5810e0a6a345b7d78549de7676ae5b2662 to c50d6515bffb148c2c12be6d587ec201dfab4c34 (excl.)
  • affected from 6db96e5810e0a6a345b7d78549de7676ae5b2662 to df2eb59fd9eb33663dc1053f5a4ed851e0aa1f67 (excl.)
  • affected from 6db96e5810e0a6a345b7d78549de7676ae5b2662 to 8439bf262ce3267bcfee29d3c61605f1731a2271 (excl.)
  • affected from 6db96e5810e0a6a345b7d78549de7676ae5b2662 to 45341b341642c377192c95e4d48e0a859cf85f42 (excl.)
  • affected from 6db96e5810e0a6a345b7d78549de7676ae5b2662 to 5d132990475f02cfa1debe03d50b479432864ebd (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.8 is affected
  • unaffected from 0 to 5.8 (excl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References