CVE-2026-64221
In the Linux kernel, the following vulnerability has been resolved: spi: ti-qspi: fix use-after-free after DMA setup failure The driver falls back to PIO mode if DMA setup fails during probe.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: spi: ti-qspi: fix use-after-free after DMA setup failure The driver falls back to PIO mode if DMA setup fails during probe. Make sure to clear the DMA channel pointer also if buffer allocation fails to avoid passing a pointer to the released channel to the DMA engine (or trying to free the channel a second time on late probe errors or driver unbind). This issue was flagged by Sashiko when reviewing a devres allocation conversion patch.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/178b9b570c0f75fa7e691490520328b20d19138ePatch
- https://git.kernel.org/stable/c/1cd927002120678bd5d23c760246639caa53040ePatch
- https://git.kernel.org/stable/c/3bbbe7ae3fdada0df4157c1ffe989f92dfa8dcd6Patch
- https://git.kernel.org/stable/c/9c6f306a8140962c7284197db54b96fdb5f468d6Patch
- https://git.kernel.org/stable/c/d6f422b122922d1abee907d673bcc990e5f3672dPatch
- https://git.kernel.org/stable/c/d7a076fb596c7b408ed6df74793a597990a6d860Patch
- https://git.kernel.org/stable/c/ea6ec3343e05f7937a53eb6d7617b3abdb4abc19Patch
- https://git.kernel.org/stable/c/f2dc841d7dc9063fe9b47ced869b1271e55052aePatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.