CVE-2026-98208

Summary

In the Linux kernel, the following vulnerability has been resolved:

mmc: sdio_uart: fix xmit_fifo leak when the port table is full

sdio_uart_add_port() allocates the transmit fifo before claiming a slot in sdio_uart_table[]. When all UART_NR slots are taken, it returns -EBUSY with the fifo still allocated, but the probe error path only kfree()s the port, leaking the transmit fifo.

Free the fifo in the failure path of sdio_uart_add_port() itself so the function retains nothing on error.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux8b197a5ce7a7218bb9fc721647ba0d5734f27348 < 9e992d59138fcfaa4bad7cc0750265b0a8bca100affected
LinuxLinux8b197a5ce7a7218bb9fc721647ba0d5734f27348 < b97b5b66c93cb4aaf6358727a73fff880a774dfdaffected
LinuxLinux8b197a5ce7a7218bb9fc721647ba0d5734f27348 < 8a2c1bf209ba04cbd14153a771724bd5aa522fcdaffected
LinuxLinux8b197a5ce7a7218bb9fc721647ba0d5734f27348 < 72f4c2b7a48423c708f2c348585419a1b71ab04caffected
LinuxLinux8b197a5ce7a7218bb9fc721647ba0d5734f27348 < fd8223c53ad9553b2a349d2a40e19bbc6e60fc48affected
LinuxLinux8b197a5ce7a7218bb9fc721647ba0d5734f27348 < ac866db277a4c73e84b4263773652e3aba326249affected
LinuxLinux8b197a5ce7a7218bb9fc721647ba0d5734f27348 < 5e142adbbdc54afbd01fad476c91cded41d22594affected
LinuxLinux8b197a5ce7a7218bb9fc721647ba0d5734f27348 < 53823e25793a97d07e6e98e0904bbf74cac8bc76affected
LinuxLinux2.6.34affected
LinuxLinux0 < 2.6.34unaffected
LinuxLinux5.10.271 <= 5.10.*unaffected
LinuxLinux5.15.222 <= 5.15.*unaffected
LinuxLinux6.1.189 <= 6.1.*unaffected
LinuxLinux6.6.158 <= 6.6.*unaffected
LinuxLinux6.12.112 <= 6.12.*unaffected
LinuxLinux6.18.54 <= 6.18.*unaffected
LinuxLinux7.2.8 <= 7.2.*unaffected
LinuxLinux7.3-rc4 <= *unaffected

Weaknesses

References