Answer in brief
CVE-2026-98212 records a Unknown severity vulnerability in mmc: hsq: Fix use-after-free in retry work. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6db96e5810e0a6a345b7d78549de7676ae5b2662 <c50d6515bffb148c2c12be6d587ec201dfab4c34 || >=6db96e5810e0a6a345b7d78549de7676ae5b2662 <df2eb59fd9eb33663dc1053f5a4ed851e0aa1f67 || >=6db96e5810e0a6a345b7d78549de7676ae5b2662 <8439bf262ce3267bcfee29d3c61605f1731a2271 || >=6db96e5810e0a6a345b7d78549de7676ae5b2662 <45341b341642c377192c95e4d48e0a859cf85f42 || >=6db96e5810e0a6a345b7d78549de7676ae5b2662 <5d132990475f02cfa1debe03d50b479432864ebd | c50d6515bffb148c2c12be6d587ec201dfab4c34, df2eb59fd9eb33663dc1053f5a4ed851e0aa1f67, 8439bf262ce3267bcfee29d3c61605f1731a2271, 45341b341642c377192c95e4d48e0a859cf85f42, 5d132990475f02cfa1debe03d50b479432864ebd |
| Linux/Linuxgeneric | 5.8 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: mmc: hsq: Fix use-after-free in retry work mmc_hsq_pump_requests() queues retry_work when request_atomic() returns -EBUSY; today sdhci-sprd is the only consumer that implements request_atomic(). The work is embedded in a devm-allocated mmc_hsq, but is never cancelled during driver removal. Work still pending at unbind can therefore run after the devm allocation has been released and dereference hsq->mmc and hsq->mrq. Use devm_work_autocancel() to cancel and drain retry_work before the devm allocation is released. By the time devres cleanup begins, mmc_remove_host() has already stopped the host, so no new requests can arm the work. This issue was found by an in-house static analysis tool.
Quoted source text, attributed separately from HOL analysis.