Back

HIGH

spi: fix use-after-free on controller registration failure

Published Apr 3, 2026

Description

Make sure to deregister from driver core also in the unlikely event that per-cpu statistics allocation fails during controller registration to avoid use-after-free (of driver resources) and unclocked register accesses.

Affected products

Remediation

Red Hat statement

This vulnerability occurs only during an unlikely error path when per-CPU statistics allocation fails during SPI controller registration. Under normal system operation with adequate memory, this path is not exercised. The practical exploitability is very limited as it requires triggering a specific allocation failure during driver initialization.

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Apr 3, 2026
Updated Sep 8, 2026
Reserved Mar 9, 2026
NVD
Status Modified
Modified Jul 24, 2026
Red Hat
Severity Moderate
Public date Apr 3, 2026
ENISA EUVD
Assigner Linux
Published Apr 3, 2026
Updated Sep 8, 2026
Exploited since n/a
EUVD-2026-18761