{"api_version":"1","generated_at":"2026-09-12T10:56:37+00:00","cve":"CVE-2026-89440","urls":{"html":"https://cve.report/CVE-2026-89440","api":"https://cve.report/api/cve/CVE-2026-89440.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89440","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89440"},"summary":{"title":"mmc: via-sdmmc: stop card-detect handling on probe failure","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: via-sdmmc: stop card-detect handling on probe failure\n\nrequest_irq() registers the SD card-detect interrupt and the probe enables\nit before mmc_add_host() runs. If mmc_add_host() fails, the error path only\nunmaps the registers and returns: the interrupt stays registered, so the\nhandler keeps running against the host once it is freed. via_sdc_isr()\ndereferences sdhost and its MMIO base and schedules carddet_work, which\nvia_sdc_card_detect() also runs against freed memory through its\ncontainer_of() dereference.\n\nAdd a probe-error path that disables and frees the interrupt and cancels\ncarddet_work before unmapping. carddet_work can re-enable the device\ninterrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it\nagain after cancelling the work.\n\nThis issue was found by an in-house static analysis tool and confirmed by\nmanual code review.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-11 20:19:24","updated_at":"2026-09-11 20:19:24"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/c2b8a624911999399cc14822fec3e35032b3cee4","name":"https://git.kernel.org/stable/c/c2b8a624911999399cc14822fec3e35032b3cee4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/efe7f25dd27e35063477b4b0e7eed3675669fd99","name":"https://git.kernel.org/stable/c/efe7f25dd27e35063477b4b0e7eed3675669fd99","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/088eaa92fcebaa6b957ccf9635afdf39643a577d","name":"https://git.kernel.org/stable/c/088eaa92fcebaa6b957ccf9635afdf39643a577d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2550f89589caad7402d618d7dffc038582c94b6b","name":"https://git.kernel.org/stable/c/2550f89589caad7402d618d7dffc038582c94b6b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89440","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89440","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e4e46fb61e3bb4628170810d3f2b996b709b90d9 efe7f25dd27e35063477b4b0e7eed3675669fd99 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e4e46fb61e3bb4628170810d3f2b996b709b90d9 2550f89589caad7402d618d7dffc038582c94b6b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e4e46fb61e3bb4628170810d3f2b996b709b90d9 c2b8a624911999399cc14822fec3e35032b3cee4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e4e46fb61e3bb4628170810d3f2b996b709b90d9 088eaa92fcebaa6b957ccf9635afdf39643a577d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 076bcd2c93e16b05c10564e299d6e5d26a766d00 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 12b8e81b77c05c658efd9cde3585bbd65ae39b59 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 95025a8dd0ec015872f6c16473fe04d6264e68ca git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f59ef2a47a228e51322ad76752a55a8917c56e38 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 63400da6cd37a9793c19bb6aed7131b58b975a04 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0959cc1685eb19774300d43ef25e318b457b156b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0ec94795114edc7e24ec71849dce42bfa61dafa3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected ba91b413983a9235792523c6b9f7ba2586c4d75d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.9.337 4.10 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.14.303 4.15 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.19.270 4.20 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.4.229 5.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.10.163 5.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15.86 5.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.0.16 6.1 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.1.2 6.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.2","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.109 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.50 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.4 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/mmc/host/via-sdmmc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"efe7f25dd27e35063477b4b0e7eed3675669fd99","status":"affected","version":"e4e46fb61e3bb4628170810d3f2b996b709b90d9","versionType":"git"},{"lessThan":"2550f89589caad7402d618d7dffc038582c94b6b","status":"affected","version":"e4e46fb61e3bb4628170810d3f2b996b709b90d9","versionType":"git"},{"lessThan":"c2b8a624911999399cc14822fec3e35032b3cee4","status":"affected","version":"e4e46fb61e3bb4628170810d3f2b996b709b90d9","versionType":"git"},{"lessThan":"088eaa92fcebaa6b957ccf9635afdf39643a577d","status":"affected","version":"e4e46fb61e3bb4628170810d3f2b996b709b90d9","versionType":"git"},{"status":"affected","version":"076bcd2c93e16b05c10564e299d6e5d26a766d00","versionType":"git"},{"status":"affected","version":"12b8e81b77c05c658efd9cde3585bbd65ae39b59","versionType":"git"},{"status":"affected","version":"95025a8dd0ec015872f6c16473fe04d6264e68ca","versionType":"git"},{"status":"affected","version":"f59ef2a47a228e51322ad76752a55a8917c56e38","versionType":"git"},{"status":"affected","version":"63400da6cd37a9793c19bb6aed7131b58b975a04","versionType":"git"},{"status":"affected","version":"0959cc1685eb19774300d43ef25e318b457b156b","versionType":"git"},{"status":"affected","version":"0ec94795114edc7e24ec71849dce42bfa61dafa3","versionType":"git"},{"status":"affected","version":"ba91b413983a9235792523c6b9f7ba2586c4d75d","versionType":"git"},{"lessThan":"4.10","status":"affected","version":"4.9.337","versionType":"semver"},{"lessThan":"4.15","status":"affected","version":"4.14.303","versionType":"semver"},{"lessThan":"4.20","status":"affected","version":"4.19.270","versionType":"semver"},{"lessThan":"5.5","status":"affected","version":"5.4.229","versionType":"semver"},{"lessThan":"5.11","status":"affected","version":"5.10.163","versionType":"semver"},{"lessThan":"5.16","status":"affected","version":"5.15.86","versionType":"semver"},{"lessThan":"6.1","status":"affected","version":"6.0.16","versionType":"semver"},{"lessThan":"6.2","status":"affected","version":"6.1.2","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/mmc/host/via-sdmmc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.2"},{"lessThan":"6.2","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.109","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.50","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.109","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.50","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.4","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9.337","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14.303","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.270","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.229","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.163","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.86","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0.16","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: via-sdmmc: stop card-detect handling on probe failure\n\nrequest_irq() registers the SD card-detect interrupt and the probe enables\nit before mmc_add_host() runs. If mmc_add_host() fails, the error path only\nunmaps the registers and returns: the interrupt stays registered, so the\nhandler keeps running against the host once it is freed. via_sdc_isr()\ndereferences sdhost and its MMIO base and schedules carddet_work, which\nvia_sdc_card_detect() also runs against freed memory through its\ncontainer_of() dereference.\n\nAdd a probe-error path that disables and frees the interrupt and cancels\ncarddet_work before unmapping. carddet_work can re-enable the device\ninterrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it\nagain after cancelling the work.\n\nThis issue was found by an in-house static analysis tool and confirmed by\nmanual code review."}],"providerMetadata":{"dateUpdated":"2026-09-11T19:43:09.402Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/efe7f25dd27e35063477b4b0e7eed3675669fd99"},{"url":"https://git.kernel.org/stable/c/2550f89589caad7402d618d7dffc038582c94b6b"},{"url":"https://git.kernel.org/stable/c/c2b8a624911999399cc14822fec3e35032b3cee4"},{"url":"https://git.kernel.org/stable/c/088eaa92fcebaa6b957ccf9635afdf39643a577d"}],"title":"mmc: via-sdmmc: stop card-detect handling on probe failure","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89440","datePublished":"2026-09-11T19:43:09.402Z","dateReserved":"2026-09-11T19:38:34.703Z","dateUpdated":"2026-09-11T19:43:09.402Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-11 20:19:24","lastModifiedDate":"2026-09-11 20:19:24","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89440","Ordinal":"1","Title":"mmc: via-sdmmc: stop card-detect handling on probe failure","CVE":"CVE-2026-89440","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89440","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: via-sdmmc: stop card-detect handling on probe failure\n\nrequest_irq() registers the SD card-detect interrupt and the probe enables\nit before mmc_add_host() runs. If mmc_add_host() fails, the error path only\nunmaps the registers and returns: the interrupt stays registered, so the\nhandler keeps running against the host once it is freed. via_sdc_isr()\ndereferences sdhost and its MMIO base and schedules carddet_work, which\nvia_sdc_card_detect() also runs against freed memory through its\ncontainer_of() dereference.\n\nAdd a probe-error path that disables and frees the interrupt and cancels\ncarddet_work before unmapping. carddet_work can re-enable the device\ninterrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it\nagain after cancelling the work.\n\nThis issue was found by an in-house static analysis tool and confirmed by\nmanual code review.","Type":"Description","Title":"mmc: via-sdmmc: stop card-detect handling on probe failure"}]}}}