-

CVE-2026-90410

spi: davinci: switch to managed controller allocation

In the Linux kernel, the following vulnerability has been resolved:

spi: davinci: switch to managed controller allocation

The controller is allocated with the non-managed spi_alloc_host() while
the interrupt is registered with devm_request_threaded_irq().  During
removal, spi_bitbang_stop() only unregisters the controller; the
subsequent spi_controller_put() then frees the controller together with
its embedded davinci_spi devdata, which is the IRQ handler's dev_id.
The devm_request_threaded_irq() release action (free_irq()), which
drains the handler, does not run until after .remove() returns.  A late
or latched interrupt can therefore reach davinci_spi_irq() and
dereference already-freed memory.

Switch to devm_spi_alloc_host() so that the devres LIFO order releases
the controller only after free_irq() has drained the handler, and drop
the now-redundant spi_controller_put() from .remove().  The probe error
path is simplified to direct returns.

The clock is acquired with devm_clk_get_enabled(), which is registered
after the IRQ and thus released before it by the devres LIFO order.
Drain the interrupt explicitly with devm_free_irq() before disabling the
controller so that a late interrupt cannot access the registers of a
clock-gated controller.

This issue was found by an in-house static analysis tool.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5b3bb5963ff23a344062aba04937533a6f575761
Version < 29e37f768f35592e26477f703649bd2e6f18d857
Status affected
Version 5b3bb5963ff23a344062aba04937533a6f575761
Version < f9452eba71fbfcee55c0b8e030ee3615e9f75f65
Status affected
Version 5b3bb5963ff23a344062aba04937533a6f575761
Version < 3b544072185c3d19ddec621ec9f6897ea2d10ee3
Status affected
Version 5b3bb5963ff23a344062aba04937533a6f575761
Version < 1a7958ce58dc95b06615df00c120ece4eb9ccc86
Status affected
Version 5b3bb5963ff23a344062aba04937533a6f575761
Version < ea408a05dc8f18b4a184b88d6e19d2fd1acc1527
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.14
Status affected
Version 0
Version < 3.14
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.065
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/29e37f768f35592e26477f703649bd2e6f18d857
https://git.kernel.org/stable/c/f9452eba71fbfcee55c0b8e030ee3615e9f75f65
https://git.kernel.org/stable/c/3b544072185c3d19ddec621ec9f6897ea2d10ee3
https://git.kernel.org/stable/c/1a7958ce58dc95b06615df00c120ece4eb9ccc86
https://git.kernel.org/stable/c/ea408a05dc8f18b4a184b88d6e19d2fd1acc1527