Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98210— mmc: mxcmmc: cancel data work and watchdog on remove

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: mmc: mxcmmc:在移除设备时取消数据工作和看门狗定时器 函数通过 (设备资源管理)机制的清理流程来释放主机资源,但它以及 都没有处理驱动程序自身的异步状态。 是一个在 的 DMA 路径中被激活的 10 秒定时器,它仅在 DMA 完成路径和中断(IRQ)完成路径中被删除。然而,移除(remove)路径并未显式地清空这些状态,因此该定时器可能在主机资源已被释放之后仍然触发,并在 回调中解引用已释放的主机指针,导致危险行为。 是在 PIO(程序输入/输出)路径的中断处理程

AI Predicted 6.5 Difficulty: Theoretical EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux f6ad0a481342223b2e7ae9f55b154e14f1391ada< 740f595f8ad678cb4d79f13edd12851df2492bdd affected
f6ad0a481342223b2e7ae9f55b154e14f1391ada< d3641afe6ee76d852834a34ef0669eefced32752 affected
f6ad0a481342223b2e7ae9f55b154e14f1391ada< 314966b490323bdcfd3162a1398b00e587e0ced4 affected
f6ad0a481342223b2e7ae9f55b154e14f1391ada< ae10838a7cdf0e54caa9d0a4f488704fd04e7f01 affected
f6ad0a481342223b2e7ae9f55b154e14f1391ada< a1ff367e0dc961d73707add508a95df5c3509bd1 affected
f6ad0a481342223b2e7ae9f55b154e14f1391ada< 23383e0578b58ba2dc0730cf9f7806bd66bf859a affected
f6ad0a481342223b2e7ae9f55b154e14f1391ada< e2948c4232209e87c861a680f20f1e3cf8a57fec affected
f6ad0a481342223b2e7ae9f55b154e14f1391ada< d3a421c82412344022982d5b91ba23194a0a6f29 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98210

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mmc: mxcmmc: cancel data work and watchdog on remove
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mmc: mxcmmc: cancel data work and watchdog on remove mxcmci_remove() frees the host through the devm tail, but neither it nor mmc_remove_host() drains the driver's own asynchronous state. host->watchdog, a 10 s timer armed on the DMA path in mxcmci_setup_data(), is deleted only by the DMA- and IRQ-complete paths, which the remove path does not explicitly drain; it can therefore fire after the host is freed and dereference it in mxcmci_watchdog(). host->datawork, armed from the IRQ handler on the PIO path, is not cancelled by the remove path either. Free the devm-registered IRQ, then cancel datawork and delete the watchdog in mxcmci_remove(), before dma_release_channel(). Freeing the IRQ first keeps a trailing handler from re-arming datawork between the cancel and the host free. Both callbacks are non-self-rearming. This issue was found by an in-house static analysis tool.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux f6ad0a481342223b2e7ae9f55b154e14f1391ada ~ 740f595f8ad678cb4d79f13edd12851df2492bdd -
Linux Linux 3.7 -

II. Public POCs for CVE-2026-98210

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98210

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98210 (7)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98210

No comments yet


Leave a comment