{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "8b197a5ce7a7218bb9fc721647ba0d5734f27348"
            },
            {
              "fixed": "9e992d59138fcfaa4bad7cc0750265b0a8bca100"
            },
            {
              "fixed": "b97b5b66c93cb4aaf6358727a73fff880a774dfd"
            },
            {
              "fixed": "8a2c1bf209ba04cbd14153a771724bd5aa522fcd"
            },
            {
              "fixed": "72f4c2b7a48423c708f2c348585419a1b71ab04c"
            },
            {
              "fixed": "fd8223c53ad9553b2a349d2a40e19bbc6e60fc48"
            },
            {
              "fixed": "ac866db277a4c73e84b4263773652e3aba326249"
            },
            {
              "fixed": "5e142adbbdc54afbd01fad476c91cded41d22594"
            },
            {
              "fixed": "53823e25793a97d07e6e98e0904bbf74cac8bc76"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.6.34"
            },
            {
              "fixed": "5.10.271"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.222"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.189"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98208.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: sdio_uart: fix xmit_fifo leak when the port table is full\n\nsdio_uart_add_port() allocates the transmit fifo before claiming a\nslot in sdio_uart_table[].  When all UART_NR slots are taken, it\nreturns -EBUSY with the fifo still allocated, but the probe error\npath only kfree()s the port, leaking the transmit fifo.\n\nFree the fifo in the failure path of sdio_uart_add_port() itself so\nthe function retains nothing on error.",
  "id": "CVE-2026-98208",
  "modified": "2026-10-08T02:30:30.715553994Z",
  "published": "2026-10-06T08:44:45.098Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/53823e25793a97d07e6e98e0904bbf74cac8bc76"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/5e142adbbdc54afbd01fad476c91cded41d22594"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/72f4c2b7a48423c708f2c348585419a1b71ab04c"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/8a2c1bf209ba04cbd14153a771724bd5aa522fcd"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/9e992d59138fcfaa4bad7cc0750265b0a8bca100"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ac866db277a4c73e84b4263773652e3aba326249"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/b97b5b66c93cb4aaf6358727a73fff880a774dfd"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/fd8223c53ad9553b2a349d2a40e19bbc6e60fc48"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98208.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98208"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "mmc: sdio_uart: fix xmit_fifo leak when the port table is full"
}