CVE-2026-98213: mmc: core: Cancel SDIO IRQ work before freeing host
In the Linux kernel, the following vulnerability has been resolved:
mmc: core: Cancel SDIO IRQ work before freeing host
A host controller that uses sdiosignalirq() schedules host->sdioirqwork from its interrupt handler. That work is only cancelled on the suspend path (mmcsdiosuspend()), not on the remove/free path, so a worker armed just before the controller freed its IRQ can run after mmchostclassdevrelease() has freed the host and dereference it through containerof().
Cancel host->sdioirqwork in mmcfreehost(), like the existing host->detect drain added by commit 1036f69e2513 ("mmc: core: Cancel delayed work before releasing host").
This issue was found by an in-house static analysis tool.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Cancel host->sdio_irq_work in mmc_free_host() before releasing or freeing the host, so the worker cannot run after mmc_host_classdev_release() has freed it.