mmc: sdio_uart: fix xmit_fifo leak when the port table is full
Published Oct 6, 2026
No CVSS score
EPSS 0.18%
Description
sdio_uart_add_port() allocates the transmit fifo before claiming a slot in sdio_uart_table[]. When all UART_NR slots are taken, it returns -EBUSY with the fifo still allocated, but the probe error path only kfree()s the port, leaking the transmit fifo.
Free the fifo in the failure path of sdio_uart_add_port() itself so the function retains nothing on error.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 2.6.34
Unaffected
- ≥ 0, < 2.6.34
- ≥ 5.10.271, ≤ 5.10.*
- ≥ 5.15.222, ≤ 5.15.*
- ≥ 6.1.189, ≤ 6.1.*
- ≥ 6.12.112, ≤ 6.12.*
- ≥ 6.18.54, ≤ 6.18.*
- ≥ 6.6.158, ≤ 6.6.*
- ≥ 7.2.8, ≤ 7.2.*
- 7.3-rc4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (9)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93136 Advisory
- https://git.kernel.org/stable/c/53823e25793a97d07e6e98e0904bbf74cac8bc76
- https://git.kernel.org/stable/c/5e142adbbdc54afbd01fad476c91cded41d22594
- https://git.kernel.org/stable/c/72f4c2b7a48423c708f2c348585419a1b71ab04c
- https://git.kernel.org/stable/c/8a2c1bf209ba04cbd14153a771724bd5aa522fcd
- https://git.kernel.org/stable/c/9e992d59138fcfaa4bad7cc0750265b0a8bca100
- https://git.kernel.org/stable/c/ac866db277a4c73e84b4263773652e3aba326249
- https://git.kernel.org/stable/c/b97b5b66c93cb4aaf6358727a73fff880a774dfd
- https://git.kernel.org/stable/c/fd8223c53ad9553b2a349d2a40e19bbc6e60fc48
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data