CVE-2026-98213 PUBLISHED

mmc: core: Cancel SDIO IRQ work before freeing host

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

mmc: core: Cancel SDIO IRQ work before freeing host

A host controller that uses sdio_signal_irq() schedules host->sdio_irq_work from its interrupt handler. That work is only cancelled on the suspend path (mmc_sdio_suspend()), not on the remove/free path, so a worker armed just before the controller freed its IRQ can run after mmc_host_classdev_release() has freed the host and dereference it through container_of().

Cancel host->sdio_irq_work in mmc_free_host(), like the existing host->detect drain added by commit 1036f69e2513 ("mmc: core: Cancel delayed work before releasing host").

This issue was found by an in-house static analysis tool.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 682696605c7093d2800c498c04166831e5aedf87 to bae1cf4f9902b2065bd78b759c7fe6312855f05e (excl.)
  • affected from 682696605c7093d2800c498c04166831e5aedf87 to 0bf3d168a2cc20b120d6b50f0a8ac5b40ff4d589 (excl.)
  • affected from 682696605c7093d2800c498c04166831e5aedf87 to 1d6e7315ee1c992b4ca42c9b11c5ed0e925a00e0 (excl.)
  • affected from 682696605c7093d2800c498c04166831e5aedf87 to 4553b5004eca9c9eae29a421f1a9c4d5db2c9114 (excl.)
  • affected from 682696605c7093d2800c498c04166831e5aedf87 to 2a863458828ade0671c2bc2e469bbd7f2340eb03 (excl.)
  • affected from 682696605c7093d2800c498c04166831e5aedf87 to 6feadbecdae60a6324c967f3b1493741083793a3 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.13 is affected
  • unaffected from 0 to 4.13 (excl.)
  • unaffected from 6.1.189 to 6.1.* (incl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References