Impact
The flaw lies in the Davinci SPI driver in the Linux kernel. The controller is allocated with spi_alloc_host() while the interrupt is registered with the managed function devm_request_threaded_irq(). During removal, the controller is unregistered and then freed, but free_irq() is not executed until after the .remove() function returns. Because of this LIFO release order mismatch, a late or latched interrupt can be delivered after the controller has been freed. The interrupt handler then dereferences the freed memory, causing a use‑after‑free that can trigger a kernel crash or give an attacker the ability to execute code with kernel privileges.
Affected Systems
The defect exists in the Linux kernel’s Davinci SPI controller driver wherever the driver is compiled. No specific kernel releases are enumerated, but all kernels containing this driver version are affected because the driver does not use devm_spi_alloc_host() and does not drop spi_controller_put() from .remove().
Risk and Exploitability
The CVSS severity is high for a use‑after‑free race condition, even though the EPSS score is below 1 % so large‑scale exploitation might be unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw involves kernel memory and interrupt handling, a local attacker with root privileges or the ability to load a kernel module could trigger the race by removing the device while a pending interrupt is pending. The attack vector is inferred to require local privilege; no remote exploitation scenario is stated in the description.
OpenCVE Enrichment
Debian DLA
Debian DSA