Linux vulnerability

In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: stop card-detect handling on probe failure request_irq() registers the SD card-detect interrupt and the probe enables it before mmc_add_host() runs. If mmc_add_host() fails, the error path only unmaps the registers and returns: the interrupt stays registered, so the handler keeps running against the host once it is freed. via_sdc_isr() dereferences sdhost and its MMIO base and schedules carddet_work, which via_sdc_card_detect() also runs against freed memory through its container_of() dereference. Add a probe-error path that disables and frees the interrupt and cancels carddet_work before unmapping. carddet_work can re-enable the device interrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it again after cancelling the work. This issue was found by an in-house static analysis tool and confirmed by manual code review.

Published 11 Sep 2026Updated 13 Sep 20264 sources
CVSS 7.8

What happened

In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: stop card-detect handling on probe failure request_irq() registers the SD card-detect interrupt and the probe enables it before mmc_add_host() runs. If mmc_add_host() fails, the error path only unmaps the registers and returns: the interrupt stays registered, so the handler keeps running against the host once it is freed. via_sdc_isr() dereferences sdhost and its MMIO base and schedules carddet_work, which via_sdc_card_detect() also runs against freed memory through its container_of() dereference. Add a probe-error path that disables and frees the interrupt and cancels carddet_work before unmapping. carddet_work can re-enable the device interrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it again after cancelling the work. This issue was found by an in-house static analysis tool and confirmed by manual code review.

Affected versions

Linux: e4e46fb61e3bb4628170810d3f2b996b709b90d9 through before efe7f25dd27e35063477b4b0e7eed3675669fd99 (git); e4e46fb61e3bb4628170810d3f2b996b709b90d9 through before 2550f89589caad7402d618d7dffc038582c94b6b (git); e4e46fb61e3bb4628170810d3f2b996b709b90d9 through before c2b8a624911999399cc14822fec3e35032b3cee4 (git); e4e46fb61e3bb4628170810d3f2b996b709b90d9 through before 088eaa92fcebaa6b957ccf9635afdf39643a577d (git); 076bcd2c93e16b05c10564e299d6e5d26a766d00 (git); 12b8e81b77c05c658efd9cde3585bbd65ae39b59 (git); 95025a8dd0ec015872f6c16473fe04d6264e68ca (git); f59ef2a47a228e51322ad76752a55a8917c56e38 (git); 63400da6cd37a9793c19bb6aed7131b58b975a04 (git); 0959cc1685eb19774300d43ef25e318b457b156b (git); 0ec94795114edc7e24ec71849dce42bfa61dafa3 (git); ba91b413983a9235792523c6b9f7ba2586c4d75d (git); 4.9.337 through before 4.10 (semver); 4.14.303 through before 4.15 (semver); 4.19.270 through before 4.20 (semver); 5.4.229 through before 5.5 (semver); 5.10.163 through before 5.11 (semver); 5.15.86 through before 5.16 (semver); 6.0.16 through before 6.1 (semver); 6.1.2 through before 6.2 (semver); 6.2 Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.