Junglewise Threat Intelligence

CVE-2026-46241: Linux Kernel use-after-free in mpc52xx SPI driver

CVE-2026-46241 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's SPI driver for MPC52xx processors. If the driver fails to initialize properly, it may leave active background tasks or hardware interrupts running, which can lead to a system crash or unpredictable behavior. This primarily affects the stability and reliability of industrial or embedded systems using this specific hardware.

Technical details

A use-after-free vulnerability exists in the drivers/spi/spi-mpc52xx.c component of the Linux kernel. The root cause is an improper error handling path in the mpc52xx_spi_probe function; when controller registration fails, the driver neglects to disable interrupts (irq0, irq1) and cancel pending synchronized work. This allows interrupt handlers or work queues to access memory that has already been freed or reallocated. An attacker with local access could potentially exploit this to cause a kernel panic or achieve local privilege escalation, though the primary impact is system instability. Patches have been released across multiple stable kernel branches to ensure interrupts are freed and work is cancelled during cleanup.

Affected products

  • Linux Linux Kernel 2.6.33 and later

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References

Related threats