Description
In the Linux kernel, the following vulnerability has been resolved:

spi: davinci: switch to managed controller allocation

The controller is allocated with the non-managed spi_alloc_host() while
the interrupt is registered with devm_request_threaded_irq(). During
removal, spi_bitbang_stop() only unregisters the controller; the
subsequent spi_controller_put() then frees the controller together with
its embedded davinci_spi devdata, which is the IRQ handler's dev_id.
The devm_request_threaded_irq() release action (free_irq()), which
drains the handler, does not run until after .remove() returns. A late
or latched interrupt can therefore reach davinci_spi_irq() and
dereference already-freed memory.

Switch to devm_spi_alloc_host() so that the devres LIFO order releases
the controller only after free_irq() has drained the handler, and drop
the now-redundant spi_controller_put() from .remove(). The probe error
path is simplified to direct returns.

The clock is acquired with devm_clk_get_enabled(), which is registered
after the IRQ and thus released before it by the devres LIFO order.
Drain the interrupt explicitly with devm_free_irq() before disabling the
controller so that a late interrupt cannot access the registers of a
clock-gated controller.

This issue was found by an in-house static analysis tool.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‐After‑Free leading to possible memory corruption or kernel privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The flaw lies in the Davinci SPI driver in the Linux kernel. The controller is allocated with spi_alloc_host() while the interrupt is registered with the managed function devm_request_threaded_irq(). During removal, the controller is unregistered and then freed, but free_irq() is not executed until after the .remove() function returns. Because of this LIFO release order mismatch, a late or latched interrupt can be delivered after the controller has been freed. The interrupt handler then dereferences the freed memory, causing a use‑after‑free that can trigger a kernel crash or give an attacker the ability to execute code with kernel privileges.

Affected Systems

The defect exists in the Linux kernel’s Davinci SPI controller driver wherever the driver is compiled. No specific kernel releases are enumerated, but all kernels containing this driver version are affected because the driver does not use devm_spi_alloc_host() and does not drop spi_controller_put() from .remove().

Risk and Exploitability

The CVSS severity is high for a use‑after‑free race condition, even though the EPSS score is below 1 % so large‑scale exploitation might be unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw involves kernel memory and interrupt handling, a local attacker with root privileges or the ability to load a kernel module could trigger the race by removing the device while a pending interrupt is pending. The attack vector is inferred to require local privilege; no remote exploitation scenario is stated in the description.

Generated by OpenCVE AI on September 19, 2026 at 13:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel patch that replaces spi_alloc_host() with devm_spi_alloc_host() and removes the redundant spi_controller_put() call so the controller is freed only after the IRQ handler is fully drained.
  • Reboot the system after applying the patch to ensure all driver instances are re‑initialized with the safe resource release order.
  • If an update is not immediately available, blacklist or disable the davinci_spi driver until the patch can be applied to prevent the device from being removed while pending interrupts may occur.

Generated by OpenCVE AI on September 19, 2026 at 13:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: spi: davinci: switch to managed controller allocation The controller is allocated with the non-managed spi_alloc_host() while the interrupt is registered with devm_request_threaded_irq(). During removal, spi_bitbang_stop() only unregisters the controller; the subsequent spi_controller_put() then frees the controller together with its embedded davinci_spi devdata, which is the IRQ handler's dev_id. The devm_request_threaded_irq() release action (free_irq()), which drains the handler, does not run until after .remove() returns. A late or latched interrupt can therefore reach davinci_spi_irq() and dereference already-freed memory. Switch to devm_spi_alloc_host() so that the devres LIFO order releases the controller only after free_irq() has drained the handler, and drop the now-redundant spi_controller_put() from .remove(). The probe error path is simplified to direct returns. The clock is acquired with devm_clk_get_enabled(), which is registered after the IRQ and thus released before it by the devres LIFO order. Drain the interrupt explicitly with devm_free_irq() before disabling the controller so that a late interrupt cannot access the registers of a clock-gated controller. This issue was found by an in-house static analysis tool.
Title spi: davinci: switch to managed controller allocation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:37.397Z

Reserved: 2026-09-11T19:38:34.812Z

Link: CVE-2026-90410

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:40.910

Modified: 2026-09-17T17:17:40.910

Link: CVE-2026-90410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:00:15Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free