Junglewise Threat Intelligence

CVE-2026-46148: Linux Kernel Microchip CoreQSPI improper chip select control

CVE-2026-46148 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's driver for Microchip QSPI controllers, which are used to communicate with high-speed memory and peripherals. Due to a hardware control error, the system could inadvertently activate the wrong device when multiple components were connected to the same controller. This could lead to data corruption or unintended behavior when the system attempts to read from or write to hardware components.

Technical details

The Microchip CoreQSPI driver (spi-microchip-core-qspi.c) previously relied on hardware-automated chip select (CS) management. In configurations with multiple devices where one uses the built-in CS and others use GPIO-based CS, the hardware-controlled CS would incorrectly pull low (activate) during access attempts to GPIO-based devices. This logic error stems from the hardware 'automagically' operating the CS based on transmit buffer activity regardless of the intended target. The fix involves modifying the driver to use manual software control of the built-in chip select via the DIRECT_ACCESS register and implementing the set_cs callback to ensure proper isolation between SPI devices.

Affected products

  • Linux Linux Kernel Fixed in 7672749e1496215e8683ce57cf323119033954cf, 998f43196d732f20f9b71eb6ebd973736c9fa911, ee3c99aa102212ad59dc2c19595515c4a6729307

Timeline

  • 2026-04-30: patched: Initial patch authored by Conor Dooley
  • 2026-05-28: disclosed: CVE published

References