Answer in brief
CVE-2026-80556 records a Unknown severity vulnerability in mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7d2be0749a59096a334c94dc48f43294193cb8ed <22aecf6c4721727a2f724ca0438bc7d4b609bf3f || >=7d2be0749a59096a334c94dc48f43294193cb8ed <b5060ff2f5460795a3e9f7cdf5052aa42f96ff81 || >=7d2be0749a59096a334c94dc48f43294193cb8ed <7599a73ff66d195a908f5d88b427933a9fb1c02a || >=7d2be0749a59096a334c94dc48f43294193cb8ed <c125ee35a49a0518521b52b27631eef061b8719a | 22aecf6c4721727a2f724ca0438bc7d4b609bf3f, b5060ff2f5460795a3e9f7cdf5052aa42f96ff81, 7599a73ff66d195a908f5d88b427933a9fb1c02a, c125ee35a49a0518521b52b27631eef061b8719a |
| Linux/Linuxgeneric | 2.6.27 | Not reported |
Published upstream
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 26, 2026
In the Linux kernel, the following vulnerability has been resolved: mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition In atmci_probe, &host->bh_work is bound with atmci_work_func, and atmci_interrupt, atmci_timeout_timer and atmci_dma_complete can all queue this work on system_bh_wq. If we remove the module, atmci_remove makes cleanup and the memory allocated for host with devm_kzalloc() is released after the remove callback returns, while the work mentioned above may still be pending or running. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | atmci_interrupt | queue_work(system_bh_wq, | &host->bh_work) atmci_remove | atmci_cleanup_slot(...) | atmci_writel(host, ATMCI_IDR, ~0UL) | timer_delete_sync(&host->timer) | dma_release_channel(host->dma.chan) | free_irq(platform_get_irq(pdev, 0), host) | | atmci_work_func | // use host // devm resources released after | // remove returns, host is freed | | // use host (use-after-free) Fix it by canceling the work after all the sources that can schedule it (IRQ handler, timeout timer and DMA completion callback) have been stopped, and before proceeding with the remaining cleanup in atmci_remove.
Quoted source text, attributed separately from HOL analysis.