{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89441","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.703Z","datePublished":"2026-09-11T19:43:10.083Z","dateUpdated":"2026-10-03T10:56:26.846Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:56:26.846Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: via-sdmmc: cancel card-detect work on remove\n\nDisabling the device interrupt and freeing the IRQ prevents new card-detect\nwork from being queued, but carddet_work already queued by the handler can\nstill run after via_sd_remove() returns. via_sdc_card_detect() recovers the\nhost through container_of() and dereferences its MMIO base; once remove()\nreturns the host can be freed, so that work would touch freed memory.\n\nCancel carddet_work after freeing the IRQ and before cancelling\nfinish_bh_work, which the card-detect handler can also queue. carddet_work\ncan re-enable the interrupt through via_reset_pcictrl(); mask it again\nafterwards.\n\nThis issue was found by an in-house static analysis tool and confirmed by\nmanual code review."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached from via_sd_remove() on the VIA VT9530 PCI SD/MMC host when unbind, rmmod, or PCI hot-remove leaves carddet_work pending; no network, Bluetooth, or USB hotplug path enters this teardown.\nAC:L - CIR IRQ queues carddet_work and via_sdc_card_detect() sleeps in via_reset_pcictrl while the attacker retries PCI unbind/rebind, so both sides of the missing cancel_work_sync race are attacker-controlled and retryable; such UAFs score AC:L.\nPR:L - Per CNA driver-removal UAF precedent, including sibling CVE-2026-89440 on this same via-sdmmc driver, an unprivileged local user on a machine with this PCI reader can spray the freed host while teardown proceeds; init-namespace root is not required.\nUI:N - No victim action such as mounting media or opening a file is required; the attacker queues carddet_work (or uses in-flight CIR work) and coordinates with driver removal themselves.\nS:U - The use-after-free corrupts the host kernel's via_crdr_mmc_host/mmc_host heap object within the same security authority; it is not a VM escape, IOMMU/DMA isolation bypass, or sandbox breakout.\nC:H - via_sdc_card_detect() recovers the freed via_crdr_mmc_host via container_of() and dereferences its MMIO bases, lock, and mrq; this kernel heap UAF enables arbitrary read via slab reuse.\nI:H - The dangling worker performs MMIO writes (DMA soft-reset, via_reset_pcictrl), may queue finish_bh_work, and can re-enable PCIINTCTRL after free_irq, yielding heap-spray write and control-flow hijack primitives.\nA:H - Use-after-free of sdhost after iounmap and devm mmc_free_host causes a kernel oops or panic even when not fully exploited, so availability impact is High."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/mmc/host/via-sdmmc.c"],"versions":[{"version":"f0bf7f61b8405224bc52fc9a3ccd167a68126e00","lessThan":"0a3c70191868fb007c03ff79693ad4e4b3fdcbb8","status":"affected","versionType":"git"},{"version":"f0bf7f61b8405224bc52fc9a3ccd167a68126e00","lessThan":"f7ff3027ef004a331ef911a4886f12bc2e996037","status":"affected","versionType":"git"},{"version":"f0bf7f61b8405224bc52fc9a3ccd167a68126e00","lessThan":"eaca730c6f5e3609df62a0469fb789235a93d276","status":"affected","versionType":"git"},{"version":"f0bf7f61b8405224bc52fc9a3ccd167a68126e00","lessThan":"57e5d877f898d5e5c9d672a77bb6bdd24f0d9bf5","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/mmc/host/via-sdmmc.c"],"versions":[{"version":"2.6.31","status":"affected"},{"version":"0","lessThan":"2.6.31","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.31","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.31","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.31","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.31","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0a3c70191868fb007c03ff79693ad4e4b3fdcbb8"},{"url":"https://git.kernel.org/stable/c/f7ff3027ef004a331ef911a4886f12bc2e996037"},{"url":"https://git.kernel.org/stable/c/eaca730c6f5e3609df62a0469fb789235a93d276"},{"url":"https://git.kernel.org/stable/c/57e5d877f898d5e5c9d672a77bb6bdd24f0d9bf5"}],"title":"mmc: via-sdmmc: cancel card-detect work on remove","x_generator":{"engine":"bippy-1.2.0"}}}}