CVE-2026-98210: mmc: mxcmmc: cancel data work and watchdog on remove

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

mmc: mxcmmc: cancel data work and watchdog on remove

mxcmciremove() frees the host through the devm tail, but neither it nor mmcremovehost() drains the driver's own asynchronous state. host->watchdog, a 10 s timer armed on the DMA path in mxcmcisetupdata(), is deleted only by the DMA- and IRQ-complete paths, which the remove path does not explicitly drain; it can therefore fire after the host is freed and dereference it in mxcmciwatchdog(). host->datawork, armed from the IRQ handler on the PIO path, is not cancelled by the remove path either.

Free the devm-registered IRQ, then cancel datawork and delete the watchdog in mxcmciremove(), before dmareleasechannel(). Freeing the IRQ first keeps a trailing handler from re-arming datawork between the cancel and the host free. Both callbacks are non-self-rearming.

This issue was found by an in-house static analysis tool.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In mxcmci_remove(), free the devm-registered IRQ first, then cancel host->datawork and delete host->watchdog before dma_release_channel(); this prevents trailing IRQ or watchdog handlers from accessing the freed host or re-arming datawork.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
Description
Data Sourced
via NVD·09:18 AM
Description
Oct 7, 2026
Data Sourced
via Microsoft·08:41 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are exposed to this issue?

Systems using the Linux kernel's mxcmmc MMC driver are affected when the driver is removed while its DMA watchdog timer or PIO data work may still be pending. The issue concerns asynchronous driver state that can outlive the host object during removal.

2

What condition triggers the unsafe behavior?

A driver removal must occur after the DMA path has armed the 10-second watchdog or the IRQ handler has scheduled PIO data work, but before those callbacks have completed or been drained. A pending callback can then run after the host has been freed and dereference it.

3

How can I determine whether a kernel contains the fix?

Inspect mxcmci_remove() for removal logic that frees the devm-registered IRQ first, then cancels datawork and deletes the watchdog before dma_release_channel(). The provided stable references identify commits containing the resolution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203