Executive brief
A vulnerability was identified in the Linux kernel's SPI driver for MPC52xx processors. This flaw could allow a local attacker to cause a system crash or potentially execute unauthorized code when the driver is unloaded or disconnected. The issue stems from a race condition where background tasks continue to run after the driver's memory has been freed.
Technical details
A use-after-free vulnerability exists in the Linux kernel's spi-mpc52xx.c driver. The root cause is a race condition during the driver's 'remove' (unbind) process: the state machine work, which is scheduled by the interrupt handler, was being cancelled before the interrupts were disabled. This allowed a late interrupt to reschedule work that would then attempt to access driver data structures after they had been freed. An attacker with local access could potentially exploit this to cause a kernel panic or achieve local privilege escalation. The fix involves reordering the cleanup sequence to ensure interrupts are freed before the work queue is synchronized and cancelled.
Affected products
- Linux Linux kernel mpc52xx SPI driver
Timeline
- 2026-04-14: other: Patch authored by Johan Hovold
- 2026-05-28: disclosed: CVE published
References
- https://git.kernel.org/stable/c/6c3e413919a12627d04a31a4a5fccb9fc129bb02
- https://git.kernel.org/stable/c/706b3dc2ac7a998c55e14b3fd2e8f934c367e6e0
- https://git.kernel.org/stable/c/bb6b50f709c5a01906ff72a07fdc070bb3357188
- https://git.kernel.org/stable/c/bbcd6dd8e9f264440eaf6167382bf404911c1c46
- https://git.kernel.org/stable/c/ee52da0dd83ebcd89ecbbe2660c57b15a25489f2