Description
In the Linux kernel, the following vulnerability has been resolved:

mmc: via-sdmmc: stop card-detect handling on probe failure

request_irq() registers the SD card-detect interrupt and the probe enables
it before mmc_add_host() runs. If mmc_add_host() fails, the error path only
unmaps the registers and returns: the interrupt stays registered, so the
handler keeps running against the host once it is freed. via_sdc_isr()
dereferences sdhost and its MMIO base and schedules carddet_work, which
via_sdc_card_detect() also runs against freed memory through its
container_of() dereference.

Add a probe-error path that disables and frees the interrupt and cancels
carddet_work before unmapping. carddet_work can re-enable the device
interrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it
again after cancelling the work.

This issue was found by an in-house static analysis tool and confirmed by
manual code review.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption (use‑after‑free) leading to a crash
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises in the Linux kernel’s MMC via‑sdmmc driver when the probe routine fails. In that scenario the interrupt that handles SD card detection remains registered and work is scheduled against freed memory, triggering a use‑after‑free that can cause a kernel crash, representing a denial‑of‑service risk.

Affected Systems

All systems running a Linux kernel that includes the MMC via‑sdmmc subsystem are potentially affected. The exact version ranges are not disclosed in the current data, so any kernel that has not yet been updated with the patch that adds the failed‑probe cleanup code may be vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. Because the flaw manifests only after a probe failure, exploitation would require an attacker to induce to the SD card interface. No public exploit has been reported, but the kernel‑service attacks.

Generated by OpenCVE AI on September 21, 2026 at 01:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to the latest release that contains the fix for the CWE-825 use‑after‑free flaw in the via‑sdmmc driver, which deregisters the interrupt and cancels pending work on probe failure.
  • If immediate kernel upgrade is not feasible, add 'blacklist sdmmc' to /etc/modprobe.d/blacklist.conf to prevent the vulnerable module from loading and thereby eliminate the CWE-825 condition.
  • Alternatively, temporarily disable the SD-card-detect interrupt in the device tree or via kernel command line parameters to avoid the use‑after‑free behavior until a patch is applied.

Generated by OpenCVE AI on September 21, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: stop card-detect handling on probe failure request_irq() registers the SD card-detect interrupt and the probe enables it before mmc_add_host() runs. If mmc_add_host() fails, the error path only unmaps the registers and returns: the interrupt stays registered, so the handler keeps running against the host once it is freed. via_sdc_isr() dereferences sdhost and its MMIO base and schedules carddet_work, which via_sdc_card_detect() also runs against freed memory through its container_of() dereference. Add a probe-error path that disables and frees the interrupt and cancels carddet_work before unmapping. carddet_work can re-enable the device interrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it again after cancelling the work. This issue was found by an in-house static analysis tool and confirmed by manual code review.
Title mmc: via-sdmmc: stop card-detect handling on probe failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:51.359Z

Reserved: 2026-09-11T19:38:34.703Z

Link: CVE-2026-89440

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:24.330

Modified: 2026-09-14T13:19:01.230

Link: CVE-2026-89440

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:09Z

Links: CVE-2026-89440 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:45:07Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference