SB2026082779 - Use-after-free in Linux kernel mmc host driver



SB2026082779 - Use-after-free in Linux kernel mmc host driver

Published: August 27, 2026

Security Bulletin ID SB2026082779
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use-after-free (CVE-ID: CVE-2026-80556)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to a use-after-free in the atmci_remove function in the atmel-mci driver when removing the module while queued or running bh_work is still pending. A local user can trigger a race condition during module removal to execute arbitrary code.

The issue arises because the interrupt handler, timeout timer, or DMA completion callback can schedule the work item before cleanup completes.


Remediation

Install update from vendor's website.