« Volver al listado

CVE-2026-97502

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

mmc: davinci: avoid NULL deref of host->data in IRQ handler

mmc_davinci_irq() returns early only when both host->cmd and host->data are NULL:

So we may legitimately reach the rest of the handler with host->data == NULL (and therefore data == NULL). The DATDNE branch already guards against this with an explicit "if (data != NULL)" check, but the subsequent TOUTRD ("read data timeout") and CRCWR/CRCRD ("data CRC error") branches dereference data unconditionally:

If either bit is set in qstatus while host->data is NULL, the kernel will crash inside the IRQ handler. smatch flags this:

Leer descripción completaMostrar menos

Gate both branches on a non-NULL data, matching the existing pattern used by the DATDNE branch.

No functional change for callers where data is non-NULL, which is the only case in which these branches did meaningful work before this change.

Detalles técnicos trazas, registros y código del informe original
  if (host->cmd == NULL && host->data == NULL) {
          ...
          return IRQ_NONE;
  }

  if (qstatus & MMCST0_TOUTRD) {
          data->error = -ETIMEDOUT;        <-- NULL deref
          ...
          davinci_abort_data(host, data);
  }

  if (qstatus & (MMCST0_CRCWR | MMCST0_CRCRD)) {
          data->error = -EILSEQ;           <-- NULL deref
          ...
  }

  drivers/mmc/host/davinci_mmc.c:933 mmc_davinci_irq() error: we
    previously assumed 'data' could be null (see line 914)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97502",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b4cff4549b7a8c5fc8b88e3493b6287555f0512c",
              "lessThan": "51738de7dd5f8e8b33dfc07ef85bc06d3bf41e96",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4cff4549b7a8c5fc8b88e3493b6287555f0512c",
              "lessThan": "f216cf00e829895ff49bdf695c944915e59bd698",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4cff4549b7a8c5fc8b88e3493b6287555f0512c",
              "lessThan": "a0cde8d70d64c1a75fbd57f01d9f2d7cccac8319",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4cff4549b7a8c5fc8b88e3493b6287555f0512c",
              "lessThan": "3c5e3e5badbf0592332887d12db02458323682c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4cff4549b7a8c5fc8b88e3493b6287555f0512c",
              "lessThan": "a01cedf230dc0fcd55b994f5e548d3982ba4c732",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4cff4549b7a8c5fc8b88e3493b6287555f0512c",
              "lessThan": "5b7e151fe9ea9311ba601849aaecdc4fc97fd577",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b4cff4549b7a8c5fc8b88e3493b6287555f0512c",
              "lessThan": "4f28846aaf8db9668e338b8987973f8935edff34",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/mmc/host/davinci_mmc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.33"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.33",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/mmc/host/davinci_mmc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:27.963",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3c5e3e5badbf0592332887d12db02458323682c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4f28846aaf8db9668e338b8987973f8935edff34",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/51738de7dd5f8e8b33dfc07ef85bc06d3bf41e96",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5b7e151fe9ea9311ba601849aaecdc4fc97fd577",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a01cedf230dc0fcd55b994f5e548d3982ba4c732",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a0cde8d70d64c1a75fbd57f01d9f2d7cccac8319",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f216cf00e829895ff49bdf695c944915e59bd698",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: davinci: avoid NULL deref of host->data in IRQ handler\n\nmmc_davinci_irq() returns early only when both host->cmd and\nhost->data are NULL:\n\n  if (host->cmd == NULL && host->data == NULL) {\n          ...\n          return IRQ_NONE;\n  }\n\nSo we may legitimately reach the rest of the handler with\nhost->data == NULL (and therefore data == NULL). The DATDNE branch\nalready guards against this with an explicit \"if (data != NULL)\"\ncheck, but the subsequent TOUTRD (\"read data timeout\") and\nCRCWR/CRCRD (\"data CRC error\") branches dereference data\nunconditionally:\n\n  if (qstatus & MMCST0_TOUTRD) {\n          data->error = -ETIMEDOUT;        <-- NULL deref\n          ...\n          davinci_abort_data(host, data);\n  }\n\n  if (qstatus & (MMCST0_CRCWR | MMCST0_CRCRD)) {\n          data->error = -EILSEQ;           <-- NULL deref\n          ...\n  }\n\nIf either bit is set in qstatus while host->data is NULL, the kernel\nwill crash inside the IRQ handler. smatch flags this:\n\n  drivers/mmc/host/davinci_mmc.c:933 mmc_davinci_irq() error: we\n    previously assumed 'data' could be null (see line 914)\n\nGate both branches on a non-NULL data, matching the existing pattern\nused by the DATDNE branch.\n\nNo functional change for callers where data is non-NULL, which is\nthe only case in which these branches did meaningful work before\nthis change."
    }
  ],
  "lastModified": "2026-10-03T11:17:59.840",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}