CVE-2026-74415
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
spi: atcspi200: fix use-after-free when driver unbind
DMA resource is initialized after SPI controller registration. So when driver unbind, this can trigger a use-after-free when DMA is torn down while the controller is still alive and triggers DMA transfers.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 34e3815ea4597131d4324a4aa243d2201e672005 < af6a34c41683067a314d2b58b39edecb2e5e4ac6 | affected |
| Linux | Linux | 34e3815ea4597131d4324a4aa243d2201e672005 < 565bdf45125a05aa8f622f58f598283f46ba43f4 | affected |
| Linux | Linux | 7.0 | affected |
| Linux | Linux | 0 < 7.0 | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/af6a34c41683067a314d2b58b39edecb2e5e4ac6
- https://git.kernel.org/stable/c/565bdf45125a05aa8f622f58f598283f46ba43f4
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.