Use-after-free in Linux kernel - CVE-2026-89440
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the via-sdmmc card-detect interrupt handler and carddet_work when handling a card-detect interrupt after mmc_add_host() fails. A local user can trigger card-detect interrupt handling against a freed host object to cause a denial of service.