spi: meson-spicc: Fix double-put in remove path
Published Apr 22, 2026
7.8
HIGHCVSS 3.1
EPSS 0.18%
Description
meson_spicc_probe() registers the controller with devm_spi_register_controller(), so teardown already drops the controller reference via devm cleanup.
Calling spi_controller_put() again in meson_spicc_remove() causes a double-put.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- ≥ 4.14.244, < 4.15
- ≥ 4.19.203, < 4.20
- ≥ 5.10.58, < 5.10.259
- ≥ 5.13.10, < 5.14
- ≥ 5.4.140, < 5.5
-
Affected
- 5.14
Unaffected
- ≥ 0, < 5.14
- ≥ 5.10.259, ≤ 5.10.*
- ≥ 5.15.209, ≤ 5.15.*
- ≥ 6.1.175, ≤ 6.1.*
- ≥ 6.12.80, ≤ 6.12.*
- ≥ 6.18.21, ≤ 6.18.*
- ≥ 6.19.11, ≤ 6.19.*
- ≥ 6.6.140, ≤ 6.6.*
- 7.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
- ≥ 4.14.244 · < 4.15
- ≥ 4.19.203 · < 4.20
- ≥ 5.4.140 · < 5.5
- ≥ 5.10.58 · < 5.11
- ≥ 5.13.10 · < 5.14
- ≥ 5.14.1 · < 6.12.80
- ≥ 6.13 · < 6.18.21
- ≥ 6.19 · < 6.19.11
- 5.14
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2026-31489 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2460729 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24857 Advisory
- https://git.kernel.org/stable/c/01f5f7976c24d6e9beef6b5a410af3b9b1d4d476
- https://git.kernel.org/stable/c/0d645c6d13fa0597935d3d16b09a7ba5d24ed284
- https://git.kernel.org/stable/c/40ad0334c17b23d8b66b1082ad1478a6202e90e2 Patch
- https://git.kernel.org/stable/c/63542bb402b7013171c9f621c28b609eda4dbf1f Patch
- https://git.kernel.org/stable/c/7434c64ddae88a02e7fb478bc256cc100d48d3e3
- https://git.kernel.org/stable/c/9b812ceb75a6260c17c91db4b9e74ead8cfa06f5 Patch
- https://git.kernel.org/stable/c/d61bcec3aec6f0244a9b963e0c76c00f771d49b6
- https://git.kernel.org/stable/c/da06a104f0486355073ff0d1bcb1fcbebb7080d6 Patch
- https://lore.kernel.org/linux-cve-announce/2026042201-CVE-2026-31489-3a01@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-31489
- https://www.cve.org/CVERecord?id=CVE-2026-31489
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data