Junglewise Threat Intelligence

CVE-2026-31485: Linux Kernel use after free in fsl-lpspi SPI driver

CVE-2026-31485 · Severity: high · CVSS 7.8 · Published 2026-04-22

Technologies: Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's SPI driver for Freescale LPSPI controllers can lead to a system crash or potential data corruption. This occurs because the system may attempt to use hardware resources after they have already been shut down during a driver removal process. This could impact the reliability and availability of industrial control systems or embedded devices using this specific hardware.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel SPI driver (spi-fsl-lpspi) due to an improper teardown sequence in the fsl_lpspi_remove() function. The driver used devm_spi_register_controller(), which delays unregistration until after the remove function returns, but the remove function synchronously tears down DMA channels. If an SPI transfer is active during driver removal, it triggers a NULL pointer dereference when attempting to access the freed DMA resources. This is a local vulnerability requiring low privileges to trigger via IOCTL calls (e.g., through spidev). The fix involves switching to manual controller registration and ensuring unregistration occurs before DMA teardown.

Affected products

  • Linux Linux Kernel Fixed in versions 15650df, adb2533, b341c11, ca4483f, d5d01f2, e3fd54f, e89e2b9, fbe6f40
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6

Timeline

  • 2026-03-19: patched: Initial patch authored by Marc Kleine-Budde
  • 2026-04-22: advisory: CVE-2026-31485 published

References

Related threats