Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98208— mmc: sdio_uart: fix xmit_fifo leak when the port table is full

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: mmc: sdio_uart:当端口表已满时修复 xmit_fifo 内存泄漏 sdio_uart_add_port() 在从 sdio_uart_table[] 中分配槽位之前,会分配传输 FIFO(xmit_fifo)。当所有 UART_NR 个槽位均已被占用时,该函数会返回 -EBUSY 错误,但此时 FIFO 仍然处于已分配状态。然而,探测(probe)错误处理路径仅释放了端口(port)结构体,导致传输 FIFO 被泄漏。 通过在 sdio_uart_add_po

AI Predicted 5.5 Difficulty: Moderate EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 8b197a5ce7a7218bb9fc721647ba0d5734f27348< 9e992d59138fcfaa4bad7cc0750265b0a8bca100 affected
8b197a5ce7a7218bb9fc721647ba0d5734f27348< b97b5b66c93cb4aaf6358727a73fff880a774dfd affected
8b197a5ce7a7218bb9fc721647ba0d5734f27348< 8a2c1bf209ba04cbd14153a771724bd5aa522fcd affected
8b197a5ce7a7218bb9fc721647ba0d5734f27348< 72f4c2b7a48423c708f2c348585419a1b71ab04c affected
8b197a5ce7a7218bb9fc721647ba0d5734f27348< fd8223c53ad9553b2a349d2a40e19bbc6e60fc48 affected
8b197a5ce7a7218bb9fc721647ba0d5734f27348< ac866db277a4c73e84b4263773652e3aba326249 affected
8b197a5ce7a7218bb9fc721647ba0d5734f27348< 5e142adbbdc54afbd01fad476c91cded41d22594 affected
8b197a5ce7a7218bb9fc721647ba0d5734f27348< 53823e25793a97d07e6e98e0904bbf74cac8bc76 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98208

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mmc: sdio_uart: fix xmit_fifo leak when the port table is full
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mmc: sdio_uart: fix xmit_fifo leak when the port table is full sdio_uart_add_port() allocates the transmit fifo before claiming a slot in sdio_uart_table[]. When all UART_NR slots are taken, it returns -EBUSY with the fifo still allocated, but the probe error path only kfree()s the port, leaking the transmit fifo. Free the fifo in the failure path of sdio_uart_add_port() itself so the function retains nothing on error.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 8b197a5ce7a7218bb9fc721647ba0d5734f27348 ~ 9e992d59138fcfaa4bad7cc0750265b0a8bca100 -
Linux Linux 2.6.34 -

II. Public POCs for CVE-2026-98208

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98208

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98208 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98208

No comments yet


Leave a comment