-

CVE-2026-97502

mmc: davinci: avoid NULL deref of host->data in IRQ handler

In the Linux kernel, the following vulnerability has been resolved:

mmc: davinci: avoid NULL deref of host->data in IRQ handler

mmc_davinci_irq() returns early only when both host->cmd and
host->data are NULL:

  if (host->cmd == NULL && host->data == NULL) {
          ...
          return IRQ_NONE;
  }

So we may legitimately reach the rest of the handler with
host->data == NULL (and therefore data == NULL). The DATDNE branch
already guards against this with an explicit "if (data != NULL)"
check, but the subsequent TOUTRD ("read data timeout") and
CRCWR/CRCRD ("data CRC error") branches dereference data
unconditionally:

  if (qstatus & MMCST0_TOUTRD) {
          data->error = -ETIMEDOUT;        <-- NULL deref
          ...
          davinci_abort_data(host, data);
  }

  if (qstatus & (MMCST0_CRCWR | MMCST0_CRCRD)) {
          data->error = -EILSEQ;           <-- NULL deref
          ...
  }

If either bit is set in qstatus while host->data is NULL, the kernel
will crash inside the IRQ handler. smatch flags this:

  drivers/mmc/host/davinci_mmc.c:933 mmc_davinci_irq() error: we
    previously assumed 'data' could be null (see line 914)

Gate both branches on a non-NULL data, matching the existing pattern
used by the DATDNE branch.

No functional change for callers where data is non-NULL, which is
the only case in which these branches did meaningful work before
this change.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b4cff4549b7a8c5fc8b88e3493b6287555f0512c
Version < 51738de7dd5f8e8b33dfc07ef85bc06d3bf41e96
Status affected
Version b4cff4549b7a8c5fc8b88e3493b6287555f0512c
Version < f216cf00e829895ff49bdf695c944915e59bd698
Status affected
Version b4cff4549b7a8c5fc8b88e3493b6287555f0512c
Version < a0cde8d70d64c1a75fbd57f01d9f2d7cccac8319
Status affected
Version b4cff4549b7a8c5fc8b88e3493b6287555f0512c
Version < 3c5e3e5badbf0592332887d12db02458323682c3
Status affected
Version b4cff4549b7a8c5fc8b88e3493b6287555f0512c
Version < a01cedf230dc0fcd55b994f5e548d3982ba4c732
Status affected
Version b4cff4549b7a8c5fc8b88e3493b6287555f0512c
Version < 5b7e151fe9ea9311ba601849aaecdc4fc97fd577
Status affected
Version b4cff4549b7a8c5fc8b88e3493b6287555f0512c
Version < 4f28846aaf8db9668e338b8987973f8935edff34
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.33
Status affected
Version 0
Version < 2.6.33
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.039
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a01cedf230dc0fcd55b994f5e548d3982ba4c732
https://git.kernel.org/stable/c/5b7e151fe9ea9311ba601849aaecdc4fc97fd577
https://git.kernel.org/stable/c/4f28846aaf8db9668e338b8987973f8935edff34
https://git.kernel.org/stable/c/3c5e3e5badbf0592332887d12db02458323682c3
https://git.kernel.org/stable/c/51738de7dd5f8e8b33dfc07ef85bc06d3bf41e96
https://git.kernel.org/stable/c/a0cde8d70d64c1a75fbd57f01d9f2d7cccac8319
https://git.kernel.org/stable/c/f216cf00e829895ff49bdf695c944915e59bd698