CVE-2026-31485

HIGH EPSS 2.6%
Published Apr 22, 20262mo ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Apr 22, 2026 2mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: spi: spi-fsl-lpspi: fix teardown order issue (UAF) There is a teardown order issue in the driver. The SPI controller is registered using devm_spi_register_controller(), which delays unregistration of the SPI controller until after the fsl_lpspi_remove() function returns. As the fsl_lpspi_remove() function synchronously tears down the DMA channels, a running SPI transfer triggers the following NULL pointer dereference due to use after free: | fsl_lpspi 42550000.spi: I/O Error in DMA RX | Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [...] | Call trace: | fsl_lpspi_dma_transfer+0x260/0x340 [spi_fsl_lpspi] | fsl_lpspi_transfer_one+0x198/0x448 [spi_fsl_lpspi] | spi_transfer_one_message+0x49c/0x7c8 | __spi_pump_transfer_message+0x120/0x420 | __spi_sync+0x2c4/0x520 | spi_sync+0x34/0x60 | spidev_message+0x20c/0x378 [spidev] | spidev_ioctl+0x398/0x750 [spidev] [...] Switch from devm_spi_register_controller() to spi_register_controller() in fsl_lpspi_probe() and add the corresponding spi_unregister_controller() in fsl_lpspi_remove().

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
2.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-416 Use After Free Memory Safety

Affected Products 15

VendorProductVersionRange
linuxlinux_kernel*≥4.10.1  –  <5.10.253
linuxlinux_kernel*≥5.11  –  <5.15.203
linuxlinux_kernel*≥5.16  –  <6.1.168
linuxlinux_kernel*≥6.2  –  <6.6.131
linuxlinux_kernel*≥6.7  –  <6.12.80
linuxlinux_kernel*≥6.13  –  <6.18.21
linuxlinux_kernel*≥6.19  –  <6.19.11
linuxlinux_kernel4.10any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any

References 8

  • git.kernel.org https://git.kernel.org/stable/c/15650dfbaeeb14bcaaf053b93cf631db8d465300
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/adb25339b66112393fd6892ceff926765feb5b86
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b341c1176f2e001b3adf0b47154fc31589f7410e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ca4483f36ac1b62e69f8b182c5b8f059e0abecfb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d5d01f24bc6fbde40b4e567ef9160194b61267bc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e3fd54f8b0317fbccc103961ddd660f2a32dcf0b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e89e2b97253c124d37bf88e96e5e8ce5c3aeeec3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fbe6f40caeebb0b1ea9dfedc259124c1d3cda7a6
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/15650dfbaeeb14bcaaf053b93cf631db8d465300
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/adb25339b66112393fd6892ceff926765feb5b86
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b341c1176f2e001b3adf0b47154fc31589f7410e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ca4483f36ac1b62e69f8b182c5b8f059e0abecfb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d5d01f24bc6fbde40b4e567ef9160194b61267bc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e3fd54f8b0317fbccc103961ddd660f2a32dcf0b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e89e2b97253c124d37bf88e96e5e8ce5c3aeeec3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fbe6f40caeebb0b1ea9dfedc259124c1d3cda7a6
    Patch