CVE-2026-98212: mmc: hsq: Fix use-after-free in retry work
In the Linux kernel, the following vulnerability has been resolved:
mmc: hsq: Fix use-after-free in retry work
mmchsqpumprequests() queues retrywork when requestatomic() returns -EBUSY; today sdhci-sprd is the only consumer that implements requestatomic(). The work is embedded in a devm-allocated mmchsq, but is never cancelled during driver removal. Work still pending at unbind can therefore run after the devm allocation has been released and dereference hsq->mmc and hsq->mrq.
Use devmworkautocancel() to cancel and drain retrywork before the devm allocation is released. By the time devres cleanup begins, mmcremovehost() has already stopped the host, so no new requests can arm the work.
This issue was found by an in-house static analysis tool.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Use devm_work_autocancel() for retry_work so it is cancelled and drained before the devm-allocated mmc_hsq is released during driver removal.