Executive brief
A vulnerability in the Linux kernel's SPI (Serial Peripheral Interface) driver could cause a system crash. The issue occurs when the system attempts to log an error during a failed data transfer but finds no active message to reference, leading to a kernel panic. This could be used by a local user to disrupt system availability.
Technical details
A vulnerability exists in the Linux kernel's DesignWare SPI DMA driver (drivers/spi/spi-dw-dma.c) due to improper handling of error logging. When a DMA transaction times out in dw_spi_dma_wait(), the code attempts to log an error using a pointer from the current message (cur_msg). However, if a transaction fails or is interrupted, cur_msg may be NULL, resulting in a NULL pointer dereference and a kernel crash. The fix involves referencing the device structure from the SPI controller directly rather than the individual message. This issue affects versions from 5.8.1 up to 6.19.11 and has been patched in subsequent stable releases.
Affected products
- Linux Linux Kernel 5.8.1 to 6.19.11
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory
- 2026-03-03: patched: Initial patch authored