Description
In the Linux kernel, the following vulnerability has been resolved:

spi: oc-tiny: switch to managed controller allocation

The controller is allocated with the non-managed spi_alloc_host() while
the interrupt is registered with devm_request_irq(). During removal,
spi_bitbang_stop() only unregisters the controller; the subsequent
spi_controller_put() then frees the controller together with its
embedded driver-private devdata, which is the IRQ handler's dev_id. The
devm_request_irq() release action (free_irq()), which drains the
handler, does not run until after .remove() returns. A late or latched
interrupt can therefore reach tiny_spi_irq() and dereference
already-freed memory (e.g. hw->base).

Switch to devm_spi_alloc_host() so that the devres LIFO order releases
the controller only after free_irq() has drained the handler, and drop
the now-redundant spi_controller_put() from .remove(). The probe error
path is simplified to direct returns.

This issue was found by an in-house static analysis tool.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑Free
Action: Patch Immediately
AI Analysis

Impact

The Linux kernel’s SPI oc‑tiny driver allocates the controller with a non‑managed function while registering the interrupt handler with a managed request; during removal the driver unregisters the controller first and then frees it, but the unchecked IRQ handler release is postponed until after the .remove() routine returns. Consequently, a late or latched interrupt can be dispatched to tiny_spi_irq() while its dev_id points to already‑freed memory, leading to a kernel memory corruption that can manifest as a crash or, if exploited, as arbitrary code execution. This mismatch between resource allocation and release highlights a classic Use‑after‑Free defect (CWE‑416).

Affected Systems

Any Linux kernel installation that includes the SPI oc‑tiny driver prior to the recent commit is affected; specifically, kernels that use the legacy spi_alloc_host allocation for this driver while the IRQ handler is managed with devm_request_irq. The vulnerability is independent of hardware; any system that loads the oc‑tiny SPI module built against a vulnerable kernel version is at risk.

Risk and Exploitability

The EPSS score is reported as < 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low probability of exploitation in the wild. However, because the defect can cause kernel kernel memory corruption, its impact is high if triggered. The likely attack vector involves an interrupt delivered after the driver initiates its removal while the IRQ is still active, a scenario that could be induced by a malicious or malfunctioning SPI peripheral. Given the severity of potential kernel panic or code execution, the vulnerability warrants that it be treated as a high‑priority patch issue.

Generated by OpenCVE AI on September 19, 2026 at 13:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that implements devm_spi_alloc_host for the oc‑tiny SPI driver
  • If an upgrade cannot be performed immediately, disable or unload the oc‑tiny SPI module to prevent it from being loaded and removed while the vulnerability exists
  • Apply any vendor‑supplied firmware or driver patches that include the same resource‑management change

Generated by OpenCVE AI on September 19, 2026 at 13:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: spi: oc-tiny: switch to managed controller allocation The controller is allocated with the non-managed spi_alloc_host() while the interrupt is registered with devm_request_irq(). During removal, spi_bitbang_stop() only unregisters the controller; the subsequent spi_controller_put() then frees the controller together with its embedded driver-private devdata, which is the IRQ handler's dev_id. The devm_request_irq() release action (free_irq()), which drains the handler, does not run until after .remove() returns. A late or latched interrupt can therefore reach tiny_spi_irq() and dereference already-freed memory (e.g. hw->base). Switch to devm_spi_alloc_host() so that the devres LIFO order releases the controller only after free_irq() has drained the handler, and drop the now-redundant spi_controller_put() from .remove(). The probe error path is simplified to direct returns. This issue was found by an in-house static analysis tool.
Title spi: oc-tiny: switch to managed controller allocation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:53.085Z

Reserved: 2026-09-11T19:38:34.815Z

Link: CVE-2026-90433

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:48.400

Modified: 2026-09-17T17:17:48.400

Link: CVE-2026-90433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:45:15Z

Weaknesses