Junglewise Threat Intelligence

CVE-2026-45996: Linux Linux kernel use-after-free in i.MX SPI driver during unbind

CVE-2026-45996 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's SPI driver for i.MX processors. The issue occurs when the driver is disconnected (unbound), potentially causing the system to crash or behave unpredictably because it tries to use memory that has already been freed. This primarily affects system stability and could potentially be used to disrupt operations on devices using this specific hardware.

Technical details

A use-after-free vulnerability exists in the `spi-imx` driver within the Linux kernel. The root cause is located in the `spi_imx_remove` function, where the SPI subsystem's deregistration process automatically frees the controller and subsystem-allocated driver data if it is not device-managed. Because the driver continues to access this data (e.g., for runtime PM and SDMA cleanup) after calling `spi_unregister_controller`, it accesses freed memory. The fix involves incrementing the controller's reference count before deregistration and decrementing it only after the driver has finished its cleanup tasks. This issue affects versions starting from 5.19.

Affected products

  • Linux Linux kernel 5.19 and later

Timeline

  • 2026-03-24: disclosed: Initial patch authored by Johan Hovold
  • 2026-05-27: advisory: CVE-2026-45996 published in NVD

References

Related threats