7.8

CVE-2026-31389

spi: fix use-after-free on controller registration failure

In the Linux kernel, the following vulnerability has been resolved:

spi: fix use-after-free on controller registration failure

Make sure to deregister from driver core also in the unlikely event that
per-cpu statistics allocation fails during controller registration to
avoid use-after-free (of driver resources) and unclocked register
accesses.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 6598b91b5ac32bc756d7c3000a31f775d4ead1c4
Version < 0e23f50086da7d0b183dfeac26021acfcdee086b
Status affected
Version 6598b91b5ac32bc756d7c3000a31f775d4ead1c4
Version < 6bbd385b30c7fb6c7ee0669e9ada91490938c051
Status affected
Version 6598b91b5ac32bc756d7c3000a31f775d4ead1c4
Version < afe27c1f43aa57530011f419be6ddf71306565d2
Status affected
Version 6598b91b5ac32bc756d7c3000a31f775d4ead1c4
Version < 80f3e8cd2b4ad355b2ad2024cf423f6d183404f7
Status affected
Version 6598b91b5ac32bc756d7c3000a31f775d4ead1c4
Version < 23b51bad2eb8787aa74324cfccefb258515ae5ba
Status affected
Version 6598b91b5ac32bc756d7c3000a31f775d4ead1c4
Version < 8634e05b08ead636e926022f4a98416e13440df9
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.0
Status affected
Version 0
Version < 6.0
Status unaffected
Version <= 6.1.*
Version 6.1.167
Status unaffected
Version <= 6.6.*
Version 6.6.130
Status unaffected
Version <= 6.12.*
Version 6.12.78
Status unaffected
Version <= 6.18.*
Version 6.18.20
Status unaffected
Version <= 6.19.*
Version 6.19.10
Status unaffected
Version <= *
Version 7.0
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.