Executive brief
A vulnerability in the Linux kernel's SPI driver for Freescale LPSPI controllers can lead to a system crash or potential data corruption. This occurs because the system may attempt to use hardware resources after they have already been shut down during a driver removal process. This could impact the reliability and availability of industrial control systems or embedded devices using this specific hardware.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel SPI driver (spi-fsl-lpspi) due to an improper teardown sequence in the fsl_lpspi_remove() function. The driver used devm_spi_register_controller(), which delays unregistration until after the remove function returns, but the remove function synchronously tears down DMA channels. If an SPI transfer is active during driver removal, it triggers a NULL pointer dereference when attempting to access the freed DMA resources. This is a local vulnerability requiring low privileges to trigger via IOCTL calls (e.g., through spidev). The fix involves switching to manual controller registration and ensuring unregistration occurs before DMA teardown.
Affected products
- Linux Linux Kernel Fixed in versions 15650df, adb2533, b341c11, ca4483f, d5d01f2, e3fd54f, e89e2b9, fbe6f40
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6
Timeline
- 2026-03-19: patched: Initial patch authored by Marc Kleine-Budde
- 2026-04-22: advisory: CVE-2026-31485 published
References
- https://git.kernel.org/stable/c/15650dfbaeeb14bcaaf053b93cf631db8d465300
- https://git.kernel.org/stable/c/adb25339b66112393fd6892ceff926765feb5b86
- https://git.kernel.org/stable/c/b341c1176f2e001b3adf0b47154fc31589f7410e
- https://git.kernel.org/stable/c/ca4483f36ac1b62e69f8b182c5b8f059e0abecfb
- https://git.kernel.org/stable/c/d5d01f24bc6fbde40b4e567ef9160194b61267bc
- https://git.kernel.org/stable/c/e3fd54f8b0317fbccc103961ddd660f2a32dcf0b
- https://git.kernel.org/stable/c/e89e2b97253c124d37bf88e96e5e8ce5c3aeeec3