Description
In the Linux kernel, the following vulnerability has been resolved:

spi: Fix DMA mapping ownership on partial map failure

If RX mapping fails after TX mapping succeeds, __spi_map_msg() unmaps
TX but leaves tx_sg_mapped set. If TX mapping fails on a later
transfer, mappings created for earlier transfers remain active.

In both cases, cur_{tx,rx}_dma_dev have not yet been updated because they
are assigned only after every transfer has been mapped. The subsequent
spi_unmap_msg() may therefore unmap the TX mapping again or release
earlier mappings using a NULL or stale device. Using a NULL device can
trigger an oops. An empty SG table does not prevent the NULL dereference
because dma_unmap_sg_attrs() accesses the device before checking the
entry count.

Publish both mapping devices before mapping starts and unwind all
failures through __spi_unmap_msg(). This clears the mapping flags and
releases each mapping once with the device that created it.

Publishing the devices before the loop also refreshes them when no
transfer needs mapping. No mapping flag is set in that case, so current
users do not use the pointers as mapping owners.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash leading to Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability occurs in the Linux SPI subsystem when a DMA mapping for a device message partially fails. After a successful transmission mapping, the code clears the transmission flag but mis‑tracks ownership of the device pointers; when a subsequent mapping fails, these pointers remain stale or NULL. The later unmapping logic then attempts to unmap using that NULL or stale pointer, causing the DMA unmap function to dereference a NULL pointer before any safety checks. This results in a kernel oops and a crash, providing attackers with a denial‑of‑service capability but no direct privilege escalation or code execution.

Affected Systems

All Linux kernel images that have not incorporated the commit referenced in the advisory are affected, regardless of distribution. The bug is present in any build that still uses the legacy SPI DMA mapping logic before the fix commit, and the issue is not limited to a specific kernel version in the supplied data.

Risk and Exploitability

The CVSS base score of 9.8 indicates critical severity. The EPSS score is reported as less than 1 %, implying a low expected exploitation likelihood in typical environments. The vulnerability is not listed in the CISA KEV catalog, but the high severity warrants prompt remediation. Based on the description, it is inferred that exploitation would require the attacker to provoke a failure in an SPI DMA mapping operation, which generally requires privileged code or control over the SPI hardware. Therefore, the likely attack vector is limited to systems with exposed SPI drivers or those that allow an attacker to trigger mapping failures. The risk is higher for environments where SPI drivers are active and unmonitored.

Generated by OpenCVE AI on September 18, 2026 at 07:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the SPI DMA mapping fix, such as the commits referenced in the advisory (367cea239fc9, 5def8b6aaad4, a38051fa2dded, cc8354213ad6).
  • If an immediate kernel patch is unavailable, temporarily remove or disable any SPI driver modules that perform DMA mappings until the issue is resolved by a patch.
  • After applying the patch or disabling the vulnerable driver, monitor system logs for DMA mapping errors (e.g., dma_unmap_sg_attrs failures) to ensure the problem does not reappear.

Generated by OpenCVE AI on September 18, 2026 at 07:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux kernel
Vendors & Products Linux kernel

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership on partial map failure If RX mapping fails after TX mapping succeeds, __spi_map_msg() unmaps TX but leaves tx_sg_mapped set. If TX mapping fails on a later transfer, mappings created for earlier transfers remain active. In both cases, cur_{tx,rx}_dma_dev have not yet been updated because they are assigned only after every transfer has been mapped. The subsequent spi_unmap_msg() may therefore unmap the TX mapping again or release earlier mappings using a NULL or stale device. Using a NULL device can trigger an oops. An empty SG table does not prevent the NULL dereference because dma_unmap_sg_attrs() accesses the device before checking the entry count. Publish both mapping devices before mapping starts and unwind all failures through __spi_unmap_msg(). This clears the mapping flags and releases each mapping once with the device that created it. Publishing the devices before the loop also refreshes them when no transfer needs mapping. No mapping flag is set in that case, so current users do not use the pointers as mapping owners.
Title spi: Fix DMA mapping ownership on partial map failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Kernel Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:41:29.669Z

Reserved: 2026-09-11T19:38:34.781Z

Link: CVE-2026-90012

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:13.890

Modified: 2026-09-16T15:18:24.870

Link: CVE-2026-90012

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:45:05Z

Weaknesses