Impact
A flaw in the Linux kernel’s via‑sdmmc driver causes pending card‑detect work to be left queued after a device is removed. The queued work continues to run even though the host structure has already been freed, causing the driver to dereference a freed MMIO base. This kernel‑space use‑after‑free can corrupt memory or redirect execution, potentially allowing local privilege escalation or a denial‑of‑service crash. The vulnerability is very likely triggered by local or physical actions such as a user or attacker removing and reinserting an SD/MMC card during system operation. The CVE documentation specifies that the weakness is of type CWE‑825.
Affected Systems
The flaw affects any system running a Linux kernel that includes the via‑sdmmc driver prior to the fix introduced by commit 57e5d877f898d5e5c9d672a77bb6bdd24f0d9bf5 and its subsequent commits. All distributions, embedded systems, and appliances that ship the default kernel tree with this driver are vulnerable. Devices that support SD/MMC via a PCI controller experience the risk whenever a card is removed or reinserted while the system is running.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity local vulnerability. The EPSS score is below 1%, implying a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV. Attackers need local or physical access to trigger the flaw by removing and reinserting a card or by executing privileged code that calls via_sd_remove(). If exploited, the attacker could corrupt kernel memory, crash the system, or gain elevated privileges.
OpenCVE Enrichment