-
CVE-2026-90433
- EPSS 0.17%
- Veröffentlicht 17.09.2026 16:09:53
- Zuletzt bearbeitet 17.09.2026 17:17:48
- Erkennungen
spi: oc-tiny: switch to managed controller allocation
In the Linux kernel, the following vulnerability has been resolved: spi: oc-tiny: switch to managed controller allocation The controller is allocated with the non-managed spi_alloc_host() while the interrupt is registered with devm_request_irq(). During removal, spi_bitbang_stop() only unregisters the controller; the subsequent spi_controller_put() then frees the controller together with its embedded driver-private devdata, which is the IRQ handler's dev_id. The devm_request_irq() release action (free_irq()), which drains the handler, does not run until after .remove() returns. A late or latched interrupt can therefore reach tiny_spi_irq() and dereference already-freed memory (e.g. hw->base). Switch to devm_spi_alloc_host() so that the devres LIFO order releases the controller only after free_irq() has drained the handler, and drop the now-redundant spi_controller_put() from .remove(). The probe error path is simplified to direct returns. This issue was found by an in-house static analysis tool.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
ce792580ea2ce6f7259b45124e9ccc4574c31606
Version <
0260c94453a08491640e61f8cf0c384edbe7bd11
Status
affected
Version
ce792580ea2ce6f7259b45124e9ccc4574c31606
Version <
ef5cc4a8c088d05549f71950a72b5deff5000fd7
Status
affected
Version
ce792580ea2ce6f7259b45124e9ccc4574c31606
Version <
1cd16c8d68f58e54abb8f331d05469237200631f
Status
affected
Version
ce792580ea2ce6f7259b45124e9ccc4574c31606
Version <
d710f43ce30975d197f73c543bfe47b958d8ba17
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.39
Status
affected
Version
0
Version <
2.6.39
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.065 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/0260c94453a08491640e61f8cf0c384edbe7bd11
https://git.kernel.org/stable/c/ef5cc4a8c088d05549f71950a72b5deff5000fd7
https://git.kernel.org/stable/c/1cd16c8d68f58e54abb8f331d05469237200631f
https://git.kernel.org/stable/c/d710f43ce30975d197f73c543bfe47b958d8ba17