Executive brief
The via-sdmmc SD card host controller driver in the Linux kernel has a resource cleanup flaw during initialization failure. If the host initialization fails partway through, an interrupt handler and background worker continue running against freed memory, potentially causing kernel crashes or memory corruption. This affects systems with VIA SD card controllers that encounter probe failures.
Technical details
The vulnerability is a use-after-free in the probe error path of the via-sdmmc driver (drivers/mmc/host/via-sdmmc.c). When mmc_add_host() fails, the error handler unmaps memory but leaves the card-detect interrupt handler (via_sdc_isr) and scheduled work queue task (carddet_work) still running against the freed host structure. The interrupt handler dereferences sdhost and its MMIO base, and schedules carddet_work which also accesses freed memory via container_of(). An attacker cannot directly trigger this (it requires a legitimate probe failure), but systems with VIA SD controllers encountering initialization errors are vulnerable. The fix adds proper interrupt teardown: disabling the interrupt, calling free_irq(), and canceling the work before unmapping memory.
Affected products
- Linux Linux kernel Multiple versions; patch applied to stable branches from 5.x through 7.x
Timeline
- 2026-09-11: disclosed: CVE-2026-89440 published
- 2026-07-27: patched: Fix committed upstream (commit 088eaa92fcebaa6b957ccf9635afdf39643a577d) by Ulf Hansson
- 2026-09-07: patched: Fix merged into stable kernels by Greg Kroah-Hartman (commit 2550f89589caad7402d618d7dffc038582c94b6b)