Answer in brief
CVE-2026-98227 records a Unknown severity vulnerability in memstick: ms_block: destroy io_queue workqueue on removal. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <0ff795163f37109a134b5a421558530f8d091544 || >=0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <19c3da6621a253f1f8b937ed91bc22330a930d9c || >=0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <9a2e7cdc0880e735aff0968ee402f2c92a992b9b || >=0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <6611f78ec3fd4b33a00bfda20725b254a22979f6 || >=0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <f222bb8c30cf5699c560b29179ff2bddcac1f950 || >=0ab30494bc4f3bc1ea4659b7c5d97c5218554a63 <90af7fde083e1b22c349c3a8b1626728e44e474c | 0ff795163f37109a134b5a421558530f8d091544, 19c3da6621a253f1f8b937ed91bc22330a930d9c, 9a2e7cdc0880e735aff0968ee402f2c92a992b9b, 6611f78ec3fd4b33a00bfda20725b254a22979f6, f222bb8c30cf5699c560b29179ff2bddcac1f950, 90af7fde083e1b22c349c3a8b1626728e44e474c |
| Linux/Linuxgeneric | 3.12 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: memstick: ms_block: destroy io_queue workqueue on removal msb_init_disk() creates the per-card ordered workqueue msb->io_queue with alloc_ordered_workqueue(). It is torn down with destroy_workqueue() only on the init error path; msb_remove() never destroys it. msb_stop() merely flushes the queue, and neither msb_data_clear() nor put_disk() free it. As a result every card insert/remove cycle leaks the workqueue and its kworker, exhausting kernel memory over repeated cycles. Destroy the workqueue in msb_remove() after the disk has been removed and the queue drained.
Quoted source text, attributed separately from HOL analysis.