Description
In the Linux kernel, the following vulnerability has been resolved:

mmc: via-sdmmc: cancel card-detect work on remove

Disabling the device interrupt and freeing the IRQ prevents new card-detect
work from being queued, but carddet_work already queued by the handler can
still run after via_sd_remove() returns. via_sdc_card_detect() recovers the
host through container_of() and dereferences its MMIO base; once remove()
returns the host can be freed, so that work would touch freed memory.

Cancel carddet_work after freeing the IRQ and before cancelling
finish_bh_work, which the card-detect handler can also queue. carddet_work
can re-enable the interrupt through via_reset_pcictrl(); mask it again
afterwards.

This issue was found by an in-house static analysis tool and confirmed by
manual code review.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free leading to local privilege escalation
Action: Apply Patch
AI Analysis

Impact

A flaw in the Linux kernel’s via‑sdmmc driver causes pending card‑detect work to be left queued after a device is removed. The queued work continues to run even though the host structure has already been freed, causing the driver to dereference a freed MMIO base. This kernel‑space use‑after‑free can corrupt memory or redirect execution, potentially allowing local privilege escalation or a denial‑of‑service crash. The vulnerability is very likely triggered by local or physical actions such as a user or attacker removing and reinserting an SD/MMC card during system operation. The CVE documentation specifies that the weakness is of type CWE‑825.

Affected Systems

The flaw affects any system running a Linux kernel that includes the via‑sdmmc driver prior to the fix introduced by commit 57e5d877f898d5e5c9d672a77bb6bdd24f0d9bf5 and its subsequent commits. All distributions, embedded systems, and appliances that ship the default kernel tree with this driver are vulnerable. Devices that support SD/MMC via a PCI controller experience the risk whenever a card is removed or reinserted while the system is running.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity local vulnerability. The EPSS score is below 1%, implying a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV. Attackers need local or physical access to trigger the flaw by removing and reinserting a card or by executing privileged code that calls via_sd_remove(). If exploited, the attacker could corrupt kernel memory, crash the system, or gain elevated privileges.

Generated by OpenCVE AI on September 21, 2026 at 02:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the via‑sdmmc patch from commit 57e5d877f898d5e5c9d672a77bb6bdd24f0d9bf5.
  • If the system does not require SD/MMC support, disable or unload the via_sdcmmc driver before performing any hot removal operations.
  • Avoid removing or reinserting SD/MMC cards during normal operation; schedule card removals during maintenance windows and reboot the system to ensure any pending kernel work is cleared.

Generated by OpenCVE AI on September 21, 2026 at 02:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: cancel card-detect work on remove Disabling the device interrupt and freeing the IRQ prevents new card-detect work from being queued, but carddet_work already queued by the handler can still run after via_sd_remove() returns. via_sdc_card_detect() recovers the host through container_of() and dereferences its MMIO base; once remove() returns the host can be freed, so that work would touch freed memory. Cancel carddet_work after freeing the IRQ and before cancelling finish_bh_work, which the card-detect handler can also queue. carddet_work can re-enable the interrupt through via_reset_pcictrl(); mask it again afterwards. This issue was found by an in-house static analysis tool and confirmed by manual code review.
Title mmc: via-sdmmc: cancel card-detect work on remove
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:26.846Z

Reserved: 2026-09-11T19:38:34.703Z

Link: CVE-2026-89441

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:24.487

Modified: 2026-10-03T11:17:41.947

Link: CVE-2026-89441

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:10Z

Links: CVE-2026-89441 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:15:08Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference