SB20260828110 - Deadlock in Linux kernel mmc host driver
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Deadlock (CVE-ID: CVE-2026-80659)
CWE-ID: CWE-833 - Deadlock
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a deadlock caused by recursive mutex acquisition in the vub300 mmc host driver when handling a command response timeout and resetting the USB device. A local user can trigger a command timeout that leads to a recursive acquisition of cmd_mutex to cause a denial of service.
The issue occurs because the reset path re-enters vub300_pre_reset() while the worker thread still holds cmd_mutex.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2e6b9a394206c76dd417c991312f349435ef35e6
- https://git.kernel.org/stable/c/7ee7a77ec2f446109ab52cc80ace7acc22ab6211
- https://git.kernel.org/stable/c/8344611477c9241f45f20981990780fc5f0996f8
- https://git.kernel.org/stable/c/8672b8bdbd2063b3fcbd75f729e4706fcdad2257
- https://git.kernel.org/stable/c/9f5e04235a0b59e6e30af9f45511addf2604d757
- https://git.kernel.org/stable/c/bf9848a22a8e50d39d5e8d871581f0a8110f16b3
- https://git.kernel.org/stable/c/c2e1d33929565fa14c48d8a5a45edc3ebfc941b2
- https://git.kernel.org/stable/c/ee5fb641c4ccac8406c668d3e947eb20ce44f233